Show filters
8,625 Total Results
Displaying 191-200 of 8,625
Sort by:
Attacker Value
Unknown

CVE-2025-23920

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ApplicantPro ApplicantPro allows Reflected XSS. This issue affects ApplicantPro: from n/a through 1.3.9.
0
Attacker Value
Unknown

CVE-2024-43333

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.2.1.
0
Attacker Value
Unknown

CVE-2025-23091

Disclosure Date: February 01, 2025 (last updated February 01, 2025)
An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update.
0
Attacker Value
Unknown

CVE-2025-24831

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
0
Attacker Value
Unknown

CVE-2025-24830

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
0
Attacker Value
Unknown

CVE-2025-24829

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
0
Attacker Value
Unknown

CVE-2025-24828

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
0
Attacker Value
Unknown

CVE-2025-24827

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
0
Attacker Value
Unknown

CVE-2024-12037

Disclosure Date: January 31, 2025 (last updated January 31, 2025)
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bf_new_submission_link' shortcode in all versions up to, and including, 2.8.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-13472

Disclosure Date: January 31, 2025 (last updated February 12, 2025)
The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.9.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The same 'sc_attrs' parameter is vulnerable to Reflected Cross-Site Scripting as well.