Show filters
645 Total Results
Displaying 21-30 of 645
Sort by:
Attacker Value
Unknown

CVE-2025-22549

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pablo Cornehl WP Github allows Stored XSS.This issue affects WP Github: from n/a through 1.3.3.
0
Attacker Value
Unknown

CVE-2024-11377

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-56206

Disclosure Date: December 31, 2024 (last updated January 02, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Amarjeet Amar allows Authentication Bypass.This issue affects gap-hub-user-role: from n/a through 3.4.1.
0
Attacker Value
Unknown

CVE-2024-12867

Disclosure Date: December 20, 2024 (last updated December 21, 2024)
Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data.
0
Attacker Value
Unknown

CVE-2024-12099

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.2.0 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
Attacker Value
Unknown

CVE-2024-49420

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attackers to launch arbitrary activity.
0
Attacker Value
Unknown

CVE-2024-49419

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview.
0
Attacker Value
Unknown

CVE-2024-49418

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.
0
Attacker Value
Unknown

CVE-2024-43052

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption while processing API calls to NPU with invalid input.
Attacker Value
Unknown

CVE-2024-33056

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.