Show filters
317 Total Results
Displaying 21-30 of 317
Sort by:
Attacker Value
Unknown

CVE-2024-50534

Disclosure Date: November 19, 2024 (last updated November 20, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Syed Umair Hussain Shah World Prayer Time allows Stored XSS.This issue affects World Prayer Time: from n/a through 2.0.
0
Attacker Value
Unknown

CVE-2024-51714

Disclosure Date: November 09, 2024 (last updated November 10, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Syed Umair Hussain Shah User Password Reset allows Reflected XSS.This issue affects User Password Reset: from n/a through 1.0.
0
Attacker Value
Unknown

CVE-2024-30106

Disclosure Date: October 28, 2024 (last updated November 09, 2024)
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.
Attacker Value
Unknown

CVE-2023-50355

Disclosure Date: October 23, 2024 (last updated November 01, 2024)
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.
Attacker Value
Unknown

CVE-2024-30122

Disclosure Date: October 23, 2024 (last updated November 07, 2024)
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.
Attacker Value
Unknown

CVE-2024-49230

Disclosure Date: October 18, 2024 (last updated October 22, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Harpreet Singh Ajax Custom CSS/JS allows Reflected XSS.This issue affects Ajax Custom CSS/JS: from n/a through 2.0.4.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-30117

Disclosure Date: October 14, 2024 (last updated October 18, 2024)
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
Attacker Value
Unknown

CVE-2024-30118

Disclosure Date: October 09, 2024 (last updated October 12, 2024)
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data.
Attacker Value
Unknown

CVE-2024-23586

Disclosure Date: September 27, 2024 (last updated October 08, 2024)
HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.