Show filters
2,402 Total Results
Displaying 191-200 of 2,402
Sort by:
Attacker Value
Unknown
CVE-2024-45286
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized access that could lead to disclosure of highly sensitive data. There is no impact on integrity or availability.
0
Attacker Value
Unknown
CVE-2024-6910
Disclosure Date: September 09, 2024 (last updated February 26, 2025)
The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
0
Attacker Value
Unknown
CVE-2024-44728
Disclosure Date: September 05, 2024 (last updated February 26, 2025)
Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.
0
Attacker Value
Unknown
CVE-2024-44727
Disclosure Date: September 05, 2024 (last updated February 26, 2025)
Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.
0
Attacker Value
Unknown
CVE-2024-7884
Disclosure Date: September 05, 2024 (last updated February 26, 2025)
When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in the polling implementation of the CallFuture allows multiple references to be held for this internal state and not all references were dropped before the Future is resolved. Since we have unaccounted references held, a copy of the internal state ended up being persisted in the canister's heap and thus causing a memory leak.
Impact Canisters built in Rust with ic_cdk and ic_cdk_timers are affected. If these canisters call a canister method, use timers or heartbeat, they will likely leak a small amount of memory on every such operation. In the worst case, this could lead to heap memory exhaustion triggered by an attacker. Motoko based canisters are not affected by the bug.
PatchesThe patch has been backported to all minor versions betw…
0
Attacker Value
Unknown
CVE-2024-5957
Disclosure Date: September 05, 2024 (last updated February 26, 2025)
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
0
Attacker Value
Unknown
CVE-2024-5956
Disclosure Date: September 05, 2024 (last updated February 26, 2025)
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly
0
Attacker Value
Unknown
CVE-2024-7717
Disclosure Date: August 31, 2024 (last updated February 26, 2025)
The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2024-8016
Disclosure Date: August 30, 2024 (last updated February 26, 2025)
The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely. In certain configurations, this can be exploitable by lower level users. We confirmed that this plugin installed with Elementor makes it possible for users with contributor-level access and above to exploit this issue.
0
Attacker Value
Unknown
CVE-2024-39638
Disclosure Date: August 29, 2024 (last updated February 26, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.12.2.
0