Show filters
6,771 Total Results
Displaying 181-190 of 6,771
Sort by:
Attacker Value
Unknown

CVE-2024-12713

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password protected, private, or draft posts that they should not have access to.
Attacker Value
Unknown

CVE-2024-12112

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'add_form_Emsfb' AJAX action in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping and missing authorization checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-56447

Disclosure Date: January 08, 2025 (last updated January 14, 2025)
Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Attacker Value
Unknown

CVE-2024-56442

Disclosure Date: January 08, 2025 (last updated January 14, 2025)
Vulnerability of native APIs not being implemented in the NFC service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Attacker Value
Unknown

CVE-2024-56441

Disclosure Date: January 08, 2025 (last updated January 14, 2025)
Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Attacker Value
Unknown

CVE-2024-56440

Disclosure Date: January 08, 2025 (last updated January 14, 2025)
Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Attacker Value
Unknown

CVE-2024-56438

Disclosure Date: January 08, 2025 (last updated January 14, 2025)
Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect availability.
Attacker Value
Unknown

CVE-2023-52955

Disclosure Date: January 08, 2025 (last updated January 14, 2025)
Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Attacker Value
Unknown

CVE-2023-52954

Disclosure Date: January 08, 2025 (last updated January 14, 2025)
Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.
Attacker Value
Unknown

CVE-2023-52953

Disclosure Date: January 08, 2025 (last updated January 14, 2025)
Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.