Show filters
2,562 Total Results
Displaying 181-190 of 2,562
Sort by:
Attacker Value
Unknown

CVE-2024-5703

Disclosure Date: July 17, 2024 (last updated July 20, 2024)
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with Subscriber-level access and above, to access the API (provided it is enabled) and add, edit, and delete audience users.
Attacker Value
Unknown

CVE-2024-3779

Disclosure Date: July 16, 2024 (last updated August 22, 2024)
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
Attacker Value
Unknown

CVE-2024-6741

Disclosure Date: July 15, 2024 (last updated July 20, 2024)
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.
Attacker Value
Unknown

CVE-2024-6740

Disclosure Date: July 15, 2024 (last updated July 17, 2024)
Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks.
Attacker Value
Unknown

CVE-2024-6744

Disclosure Date: July 15, 2024 (last updated July 17, 2024)
The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remote server.
Attacker Value
Unknown

CVE-2024-6739

Disclosure Date: July 15, 2024 (last updated July 17, 2024)
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
Attacker Value
Unknown

CVE-2024-5167

Disclosure Date: July 13, 2024 (last updated July 13, 2024)
The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF attack
0
Attacker Value
Unknown

CVE-2024-35773

Disclosure Date: July 12, 2024 (last updated July 13, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (XSS).This issue affects Comment Reply Email: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2024-6172

Disclosure Date: July 02, 2024 (last updated July 04, 2024)
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2024-37252

Disclosure Date: June 26, 2024 (last updated June 26, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.
0