Show filters
167 Total Results
Displaying 21-30 of 167
Sort by:
Attacker Value
Unknown

CVE-2024-31430

Disclosure Date: April 10, 2024 (last updated April 11, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.1; BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.1.
0
Attacker Value
Unknown

CVE-2024-28917

Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2023-36483

Disclosure Date: March 16, 2024 (last updated April 02, 2024)
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data  including customer data, security system status, and event history.
0
Attacker Value
Unknown

CVE-2024-21404

Disclosure Date: February 13, 2024 (last updated January 12, 2025)
.NET Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2024-21386

Disclosure Date: February 13, 2024 (last updated January 12, 2025)
.NET Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2024-23838

Disclosure Date: January 30, 2024 (last updated February 09, 2024)
TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient used in the API classes. For applications using the SDK, requests to unexpected resources on local networks or to the internet could be made which could lead to information disclosure. The issue can be mitigated by having strict egress rules limiting the destinations to which requests can be made, and applying strict validation to any user input passed to the `truelayer-dotnet` library. Versions of TrueLayer.Client `v1.6.0` and later are not affected.
Attacker Value
Unknown

CVE-2024-21907

Disclosure Date: January 03, 2024 (last updated January 18, 2024)
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
Attacker Value
Unknown

CVE-2023-48003

Disclosure Date: December 26, 2023 (last updated January 04, 2024)
An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.
Attacker Value
Unknown

CVE-2023-49289

Disclosure Date: December 05, 2023 (last updated December 09, 2023)
Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes that are used on client-side to invoke methods on the web server. Affected versions of this package are vulnerable cross site scripting attacks. Releases before version 21.12.22.1 are affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2023-36558

Disclosure Date: November 14, 2023 (last updated January 06, 2025)
ASP.NET Core Security Feature Bypass Vulnerability