Show filters
153 Total Results
Displaying 21-30 of 153
Sort by:
Attacker Value
Unknown

CVE-2024-47622

Disclosure Date: October 05, 2024 (last updated October 06, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ILLID Advanced Woo Labels allows Stored XSS.This issue affects Advanced Woo Labels: from n/a through 2.01.
0
Attacker Value
Unknown

CVE-2024-27321

Disclosure Date: September 12, 2024 (last updated September 21, 2024)
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.
Attacker Value
Unknown

CVE-2024-27320

Disclosure Date: September 12, 2024 (last updated September 24, 2024)
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.
Attacker Value
Unknown

CVE-2024-43303

Disclosure Date: August 18, 2024 (last updated August 19, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in videousermanuals.Com White Label CMS allows Reflected XSS.This issue affects White Label CMS: from n/a through 2.7.4.
0
Attacker Value
Unknown

CVE-2023-29174

Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Missing Authorization vulnerability in NervyThemes SKU Label Changer For WooCommerce.This issue affects SKU Label Changer For WooCommerce: from n/a through 3.0.
0
Attacker Value
Unknown

CVE-2024-35675

Disclosure Date: June 08, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ILLID Advanced Woo Labels allows Cross-Site Scripting (XSS).This issue affects Advanced Woo Labels: from n/a through 1.93.
Attacker Value
Unknown

CVE-2024-0816

Disclosure Date: May 21, 2024 (last updated January 23, 2025)
The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.
0
Attacker Value
Unknown

CVE-2023-51546

Disclosure Date: May 17, 2024 (last updated February 12, 2025)
Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1.
Attacker Value
Unknown

CVE-2024-33009

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.
0
Attacker Value
Unknown

CVE-2024-4280

Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.
0