Show filters
141 Total Results
Displaying 21-30 of 141
Sort by:
Attacker Value
Unknown

CVE-2024-38856

Disclosure Date: August 05, 2024 (last updated February 26, 2025)
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
Attacker Value
Unknown

CVE-2024-32777

Disclosure Date: June 09, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint.This issue affects BizPrint: from n/a through 4.3.39.
0
Attacker Value
Unknown

CVE-2024-36104

Disclosure Date: June 04, 2024 (last updated February 26, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-32113

Disclosure Date: May 08, 2024 (last updated February 26, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
Attacker Value
Unknown

CVE-2024-1780

Disclosure Date: April 10, 2024 (last updated April 11, 2024)
The BizCalendar Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown

CVE-2024-29773

Disclosure Date: March 27, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint allows Cross-Site Scripting (XSS).This issue affects BizPrint: from n/a through 4.5.5.
0
Attacker Value
Unknown

CVE-2024-25065

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
0
Attacker Value
Unknown

CVE-2024-23946

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Attacker Value
Unknown

CVE-2024-24202

Disclosure Date: February 08, 2024 (last updated February 26, 2025)
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
Attacker Value
Unknown

CVE-2024-0558

Disclosure Date: January 15, 2024 (last updated February 26, 2025)
A vulnerability has been found in DedeBIZ 6.3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/makehtml_freelist_action.php. The manipulation of the argument startid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250726 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.