Show filters
863 Total Results
Displaying 21-30 of 863
Sort by:
Attacker Value
Unknown

CVE-2025-23363

Disclosure Date: February 11, 2025 (last updated February 11, 2025)
A vulnerability has been identified in Teamcenter (All versions < V14.3.0.0). The SSO login service of affected applications accepts user-controlled input that could specify a link to an external site. This could allow an attacker to redirect the legitimate user to an attacker-chosen URL to steal valid session data. For a successful exploit, the legitimate user must actively click on an attacker-crafted link.
Attacker Value
Unknown

CVE-2025-0930

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
Reflected Cross-Site Scripting (XSS) in TeamCal Neo, version 3.8.2. This allows an attacker to execute malicious JavaScript code, after injecting code via the ‘abs’ parameter in ‘/teamcal/src/index.php’.
0
Attacker Value
Unknown

CVE-2025-0929

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete all database information by injecting a malicious SQL statement via the ‘abs’ parameter in ‘/teamcal/src/index.php’.
0
Attacker Value
Unknown

CVE-2024-12320

Disclosure Date: January 30, 2025 (last updated February 01, 2025)
The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2025-23512

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Missing Authorization vulnerability in Team118GROUP Team 118GROUP Agent allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Team 118GROUP Agent: from n/a through 1.6.0.
0
Attacker Value
Unknown

CVE-2025-24461

Disclosure Date: January 21, 2025 (last updated January 31, 2025)
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
Attacker Value
Unknown

CVE-2025-24460

Disclosure Date: January 21, 2025 (last updated January 31, 2025)
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
Attacker Value
Unknown

CVE-2025-24459

Disclosure Date: January 21, 2025 (last updated January 31, 2025)
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
Attacker Value
Unknown

CVE-2024-12532

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.18 in widgets/bwdeb-content-switcher.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Attacker Value
Unknown

CVE-2024-12633

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.