Show filters
200 Total Results
Displaying 21-30 of 200
Sort by:
Attacker Value
Unknown
CVE-2024-29837
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.
0
Attacker Value
Unknown
CVE-2024-29836
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full access of the site.
0
Attacker Value
Unknown
CVE-2024-2306
Disclosure Date: April 09, 2024 (last updated April 10, 2024)
The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.
0
Attacker Value
Unknown
CVE-2024-29771
Disclosure Date: March 27, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Dracula Dark Mode - The Revolutionary Dark Mode Plugin For WordPress allows Stored XSS.This issue affects Dracula Dark Mode - The Revolutionary Dark Mode Plugin For WordPress: from n/a through 1.0.8.
0
Attacker Value
Unknown
CVE-2024-1898
Disclosure Date: March 05, 2024 (last updated February 15, 2025)
Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an administrator.
0
Attacker Value
Unknown
CVE-2023-6528
Disclosure Date: January 08, 2024 (last updated January 12, 2024)
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
0
Attacker Value
Unknown
CVE-2023-47784
Disclosure Date: December 20, 2023 (last updated December 28, 2023)
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.
0
Attacker Value
Unknown
CVE-2023-6264
Disclosure Date: November 22, 2023 (last updated December 01, 2023)
Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker to list the configured Devolutions Gateways endpoints.
0
Attacker Value
Unknown
CVE-2023-47772
Disclosure Date: November 20, 2023 (last updated November 28, 2023)
Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14.
0
Attacker Value
Unknown
CVE-2023-5358
Disclosure Date: November 01, 2023 (last updated November 10, 2023)
Improper access control in Report log filters feature in Devolutions Server 2023.2.10.0 and earlier allows attackers to retrieve logs from vaults or entries they are not allowed to access via the report request url query parameters.
0