Show filters
570 Total Results
Displaying 21-30 of 570
Sort by:
Attacker Value
Unknown

CVE-2024-48222

Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
Attacker Value
Unknown

CVE-2024-48218

Disclosure Date: October 25, 2024 (last updated November 01, 2024)
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
Attacker Value
Unknown

CVE-2024-49668

Disclosure Date: October 23, 2024 (last updated October 24, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Admin Verbalize WP Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through 1.0.
0
Attacker Value
Unknown

CVE-2024-9507

Disclosure Date: October 11, 2024 (last updated October 12, 2024)
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.15.2 due to improper input validation within the iconUpload function. This makes it possible for authenticated attackers, with Administrator-level access and above, to leverage a PHP filter chain attack and read the contents of arbitrary files on the server, which can contain sensitive information.
0
Attacker Value
Unknown

CVE-2024-8743

Disclosure Date: October 05, 2024 (last updated January 06, 2025)
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting.
0
Attacker Value
Unknown

CVE-2024-9513

Disclosure Date: October 04, 2024 (last updated November 14, 2024)
A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP POST Request Handler. The manipulation of the argument username leads to information exposure through discrepancy. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure is planning to release a fix in mid-October 2024.
Attacker Value
Unknown

CVE-2024-9291

Disclosure Date: September 27, 2024 (last updated October 08, 2024)
A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff. Affected is an unknown function of the file /ueditor/upload?configPath=ueditor/config.json&action=uploadfile of the component XML File Handler. The manipulation of the argument upfile leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The GitHub repository of the project did not receive an update for more than two years.
Attacker Value
Unknown

CVE-2024-9280

Disclosure Date: September 27, 2024 (last updated October 05, 2024)
A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as critical. This vulnerability affects the function fileUpload of the file FileUploadKit.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Attacker Value
Unknown

CVE-2024-9014

Disclosure Date: September 23, 2024 (last updated September 24, 2024)
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
0
Attacker Value
Unknown

CVE-2024-44677

Disclosure Date: September 10, 2024 (last updated September 26, 2024)
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.