Show filters
176 Total Results
Displaying 21-30 of 176
Sort by:
Attacker Value
Unknown

CVE-2024-44023

Disclosure Date: October 05, 2024 (last updated October 06, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABCApp Creator allows PHP Local File Inclusion.This issue affects ABCApp Creator: from n/a through 1.1.2.
0
Attacker Value
Unknown

CVE-2024-43276

Disclosure Date: August 18, 2024 (last updated September 18, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Child Theme Creator allows Reflected XSS.This issue affects Child Theme Creator: from n/a through 1.5.4.
Attacker Value
Unknown

CVE-2024-39655

Disclosure Date: August 01, 2024 (last updated August 02, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.77.
0
Attacker Value
Unknown

CVE-2024-34024

Disclosure Date: June 18, 2024 (last updated June 18, 2024)
Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine if a username is valid or not.
0
Attacker Value
Unknown

CVE-2024-33622

Disclosure Date: June 18, 2024 (last updated June 18, 2024)
Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, sensitive information may be obtained and/or the information stored in the database may be altered by a remote authenticated attacker.
0
Attacker Value
Unknown

CVE-2024-33620

Disclosure Date: June 18, 2024 (last updated June 18, 2024)
Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker.
0
Attacker Value
Unknown

CVE-2024-34430

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rashed Latif TT Custom Post Type Creator allows Stored XSS.This issue affects TT Custom Post Type Creator: from n/a through 1.0.
0
Attacker Value
Unknown

CVE-2024-2858

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
0
Attacker Value
Unknown

CVE-2024-2857

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.
0
Attacker Value
Unknown

CVE-2023-49147

Disclosure Date: December 19, 2023 (last updated January 03, 2024)
An issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a visible cmd.exe window when using the repair function of msiexec.exe. This allows an unprivileged local attacker to use a chain of actions (e.g., an oplock on faxPrnInst.log) to open a SYSTEM cmd.exe.