Show filters
3,312 Total Results
Displaying 171-180 of 3,312
Sort by:
Attacker Value
Unknown
CVE-2024-44107
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-44106
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
Insufficient server-side controls in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2024-44105
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to obtain OS credentials.
0
Attacker Value
Unknown
CVE-2024-44104
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2024-44103
Disclosure Date: September 10, 2024 (last updated September 19, 2024)
DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2024-8232
Disclosure Date: September 10, 2024 (last updated September 11, 2024)
SpiderControl SCADA Web Server has a vulnerability that could allow an
attacker to upload specially crafted malicious files without
authentication.
0
Attacker Value
Unknown
CVE-2024-7415
Disclosure Date: September 06, 2024 (last updated October 01, 2024)
The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
0
Attacker Value
Unknown
CVE-2024-7381
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site.
0
Attacker Value
Unknown
CVE-2024-7380
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all versions up to, and including, 8.6.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or delete WordPress menus.
0
Attacker Value
Unknown
CVE-2024-8413
Disclosure Date: September 04, 2024 (last updated September 06, 2024)
Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/raspcontrol . An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially hijacking their session details.
References list
0