Show filters
278 Total Results
Displaying 21-30 of 278
Sort by:
Attacker Value
Unknown

CVE-2024-11670

Disclosure Date: November 25, 2024 (last updated January 05, 2025)
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.
0
Attacker Value
Unknown

CVE-2024-10971

Disclosure Date: November 12, 2024 (last updated November 13, 2024)
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.
0
Attacker Value
Unknown

CVE-2024-51597

Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeShark ThemeShark Templates & Widgets for Elementor allows Stored XSS.This issue affects ThemeShark Templates & Widgets for Elementor: from n/a through 1.1.7.
Attacker Value
Unknown

CVE-2024-51681

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.
Attacker Value
Unknown

CVE-2024-50411

Disclosure Date: October 29, 2024 (last updated November 08, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts allows Stored XSS.This issue affects WP Abstracts: from n/a through 2.7.1.
Attacker Value
Unknown

CVE-2020-36836

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.
0
Attacker Value
Unknown

CVE-2024-8477

Disclosure Date: October 10, 2024 (last updated October 16, 2024)
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on the Init() function. This makes it possible for unauthenticated attackers to log out of a Brevo connection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-44045

Disclosure Date: October 06, 2024 (last updated October 07, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts allows Stored XSS.This issue affects WP Abstracts: from n/a through 2.6.5.
0
Attacker Value
Unknown

CVE-2024-9265

Disclosure Date: October 01, 2024 (last updated October 08, 2024)
The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent() function. This makes it possible for unauthenticated attackers to register as an administrator.
Attacker Value
Unknown

CVE-2024-46655

Disclosure Date: September 25, 2024 (last updated October 03, 2024)
A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload or URL.