Show filters
294 Total Results
Displaying 21-30 of 294
Sort by:
Attacker Value
Unknown
CVE-2024-0683
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 3.0.14. This makes it possible for unauthenticated and authenticated attackers, with subscriber-level access and above, to generate and delete labels.
0
Attacker Value
Unknown
CVE-2024-2395
Disclosure Date: March 12, 2024 (last updated February 26, 2025)
The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to generate and delete labels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-7033
Disclosure Date: February 27, 2024 (last updated February 26, 2025)
Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface Module, MELSEC iQ-R CC-Link IE TSN Master/Local Module, CC-Link IE TSN Remote I/O Module, CC-Link IE TSN Analog-Digital Converter Module, CC-Link IE TSN Digital-Analog Converter Module, CC-Link IE TSN - CC-Link IE Field Network Bridge Module, CC-Link IE TSN - AnyWireASLINK Bridge Module, CC-Link IE TSN FPGA Module, CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, MELSEC iQ-R Motion Module, MELSEC iQ-L Motion Module, MELSEC iQ-F FX5 Motion Module, MELSEC iQ-F Series CPU module, MELSEC iQ-F Series Ethernet module, MELSEC iQ-F Series Ethernet/IP module, MELSEC iQ-F Series OPC UA Module, MELSEC iQ-F Series CC-Link IE TSN master/local module, GOT2000 Series CC-Link IE TSN Communication Unit, FR-A800-E series inverters, FR-F800-E series inverters, FR-E800-E series inverters, INVERTER C…
0
Attacker Value
Unknown
CVE-2024-1886
Disclosure Date: February 26, 2024 (last updated February 26, 2025)
This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
0
Attacker Value
Unknown
CVE-2024-1885
Disclosure Date: February 26, 2024 (last updated February 26, 2025)
This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.
0
Attacker Value
Unknown
CVE-2023-23440
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
0
Attacker Value
Unknown
CVE-2023-23439
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
0
Attacker Value
Unknown
CVE-2023-23438
Disclosure Date: December 29, 2023 (last updated February 25, 2025)
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions
0
Attacker Value
Unknown
CVE-2023-41316
Disclosure Date: September 07, 2023 (last updated February 25, 2025)
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users. This unsanitized HTML ends up in invitation emails which appear as legitimate org invitations. Bad actors may direct users to malicious website or execute javascript in the context of the users browser. This vulnerability has been addressed in version 3.29.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-36307
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence
0