Show filters
126 Total Results
Displaying 21-30 of 126
Sort by:
Attacker Value
Unknown
CVE-2023-38520
Disclosure Date: June 04, 2024 (last updated June 04, 2024)
External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.
0
Attacker Value
Unknown
CVE-2024-32676
Disclosure Date: April 25, 2024 (last updated May 17, 2024)
Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Important Client Functionality.This issue affects LoginPress Pro: from n/a before 3.0.0.
0
Attacker Value
Unknown
CVE-2024-32677
Disclosure Date: April 24, 2024 (last updated April 25, 2024)
Missing Authorization vulnerability in LoginPress LoginPress Pro.This issue affects LoginPress Pro: from n/a before 3.0.0.
0
Attacker Value
Unknown
CVE-2024-31431
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Product Input Fields for WooCommerce.This issue affects Product Input Fields for WooCommerce: from n/a through 1.7.0.
0
Attacker Value
Unknown
CVE-2024-1174
Disclosure Date: March 01, 2024 (last updated March 02, 2024)
Previous versions of HP ThinPro (prior to HP ThinPro 8.0 SP 8) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.0 SP 8, which includes updates to mitigate potential vulnerabilities.
0
Attacker Value
Unknown
CVE-2023-45270
Disclosure Date: October 13, 2023 (last updated October 19, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.4.0 versions.
0
Attacker Value
Unknown
CVE-2023-4986
Disclosure Date: September 15, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic was found in Supcon InPlant SCADA up to 20230901. Affected by this vulnerability is an unknown functionality of the file Project.xml. The manipulation leads to password hash with insufficient computational effort. Local access is required to approach this attack. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-239797 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-4985
Disclosure Date: September 15, 2023 (last updated October 08, 2023)
A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown function of the file Project.xml. The manipulation leads to improper authentication. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239796. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2020-36696
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.
0
Attacker Value
Unknown
CVE-2023-24744
Disclosure Date: May 03, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in Rediker Software AdminPlus 6.1.91.00 allows remote attackers to run arbitrary code via the onload function within the application DOM.
0