Show filters
863 Total Results
Displaying 21-30 of 863
Sort by:
Attacker Value
Unknown
CVE-2025-23363
Disclosure Date: February 11, 2025 (last updated February 11, 2025)
A vulnerability has been identified in Teamcenter (All versions < V14.3.0.0). The SSO login service of affected applications accepts user-controlled input that could specify a link to an external site. This could allow an attacker to redirect the legitimate user to an attacker-chosen URL to steal valid session data. For a successful exploit, the legitimate user must actively click on an attacker-crafted link.
0
Attacker Value
Unknown
CVE-2025-0930
Disclosure Date: January 31, 2025 (last updated February 01, 2025)
Reflected Cross-Site Scripting (XSS) in TeamCal Neo, version 3.8.2. This allows an attacker to execute malicious JavaScript code, after injecting code via the ‘abs’ parameter in ‘/teamcal/src/index.php’.
0
Attacker Value
Unknown
CVE-2025-0929
Disclosure Date: January 31, 2025 (last updated February 01, 2025)
SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete all database information by injecting a malicious SQL statement via the ‘abs’ parameter in ‘/teamcal/src/index.php’.
0
Attacker Value
Unknown
CVE-2024-12320
Disclosure Date: January 30, 2025 (last updated February 01, 2025)
The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2025-23512
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Missing Authorization vulnerability in Team118GROUP Team 118GROUP Agent allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Team 118GROUP Agent: from n/a through 1.6.0.
0
Attacker Value
Unknown
CVE-2025-24461
Disclosure Date: January 21, 2025 (last updated January 31, 2025)
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
0
Attacker Value
Unknown
CVE-2025-24460
Disclosure Date: January 21, 2025 (last updated January 31, 2025)
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
0
Attacker Value
Unknown
CVE-2025-24459
Disclosure Date: January 21, 2025 (last updated January 31, 2025)
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
0
Attacker Value
Unknown
CVE-2024-12532
Disclosure Date: January 07, 2025 (last updated January 08, 2025)
The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.18 in widgets/bwdeb-content-switcher.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
0
Attacker Value
Unknown
CVE-2024-12633
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0