Show filters
393 Total Results
Displaying 21-30 of 393
Sort by:
Attacker Value
Unknown

CVE-2024-12595

Disclosure Date: January 02, 2025 (last updated January 02, 2025)
The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
0
Attacker Value
Unknown

CVE-2024-56198

Disclosure Date: December 31, 2024 (last updated February 27, 2025)
path-sanitizer is a simple lightweight npm package for sanitizing paths to prevent Path Traversal. Prior to 3.1.0, the filters can be bypassed using .=%5c which results in a path traversal. This vulnerability is fixed in 3.1.0.
0
Attacker Value
Unknown

CVE-2024-12993

Disclosure Date: December 30, 2024 (last updated February 27, 2025)
Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges.  After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
0
Attacker Value
Unknown

CVE-2024-11614

Disclosure Date: December 18, 2024 (last updated February 27, 2025)
An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.
0
Attacker Value
Unknown

CVE-2021-26279

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
Some parameters of the weather module are improperly stored, leaking some sensitive information.
0
Attacker Value
Unknown

CVE-2024-54389

Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Eduardo Chiaro addWeather allows Cross Site Request Forgery.This issue affects addWeather: from n/a through 2.5.1.
0
Attacker Value
Unknown

CVE-2023-49861

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in socialmediafeather Social Media Feather allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media Feather: from n/a through 2.1.3.
0
Attacker Value
Unknown

CVE-2024-52798

Disclosure Date: December 05, 2024 (last updated February 27, 2025)
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.
0
Attacker Value
Unknown

CVE-2024-53758

Disclosure Date: November 30, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry Lin WP MathJax allows Stored XSS.This issue affects WP MathJax: from n/a through 1.0.1.
0
Attacker Value
Unknown

CVE-2024-52490

Disclosure Date: November 28, 2024 (last updated February 27, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Pathomation allows Upload a Web Shell to a Web Server.This issue affects Pathomation: from n/a through 2.5.1.
0