Show filters
1,982 Total Results
Displaying 161-170 of 1,982
Sort by:
Attacker Value
Unknown
CVE-2023-47543
Disclosure Date: November 12, 2024 (last updated January 07, 2025)
An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.
0
Attacker Value
Unknown
CVE-2023-44255
Disclosure Date: November 12, 2024 (last updated January 22, 2025)
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
0
Attacker Value
Unknown
CVE-2024-51990
Disclosure Date: November 07, 2024 (last updated November 07, 2024)
jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outside the clone. This issue has been addressed in version 0.23.0. Users are advised to upgrade. Users unable to upgrade should avoid cloning repos from unknown sources.
0
Attacker Value
Unknown
CVE-2024-10535
Disclosure Date: November 06, 2024 (last updated November 09, 2024)
The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function in all versions up to, and including, 1.31. This makes it possible for unauthenticated attackers to delete thumbnails in the video-wc-gallery-thumb directory.
0
Attacker Value
Unknown
CVE-2024-38695
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Martin Gibson WP GoToWebinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP GoToWebinar: from n/a through 15.6.
0
Attacker Value
Unknown
CVE-2024-37456
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Noptin Newsletter Noptin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Noptin: from n/a through 3.4.2.
0
Attacker Value
Unknown
CVE-2024-37220
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in OptinlyHQ Optinly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Optinly: from n/a through 1.0.18.
0
Attacker Value
Unknown
CVE-2024-9991
Disclosure Date: October 25, 2024 (last updated October 26, 2024)
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi credentials stored on the vulnerable device.
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to the Wi-Fi network to which vulnerable device is connected.
0
Attacker Value
Unknown
CVE-2024-49373
Disclosure Date: October 22, 2024 (last updated October 31, 2024)
No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.
0
Attacker Value
Unknown
CVE-2024-9889
Disclosure Date: October 19, 2024 (last updated November 02, 2024)
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and above, to view private/draft/password protected posts, pages, and Elementor templates that they should not have access to.
0