Show filters
4,003 Total Results
Displaying 201-210 of 4,003
Sort by:
Attacker Value
Unknown

CVE-2024-41765

Disclosure Date: January 04, 2025 (last updated January 05, 2025)
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Attacker Value
Unknown

CVE-2024-41763

Disclosure Date: January 04, 2025 (last updated January 05, 2025)
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Attacker Value
Unknown

CVE-2024-10957

Disclosure Date: January 04, 2025 (last updated January 13, 2025)
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. An administrator must perform a search and replace action to trigger the exploit.
0
Attacker Value
Unknown

CVE-2023-48758

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.2.4.
0
Attacker Value
Unknown

CVE-2024-56236

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Jakob Bouchard Hestia Nginx Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through 2.4.0.
0
Attacker Value
Unknown

CVE-2024-37238

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Greg Winiarski WPAdverts – Classifieds Plugin allows Cross Site Request Forgery.This issue affects WPAdverts – Classifieds Plugin: from n/a through 2.1.2.
0
Attacker Value
Unknown

CVE-2023-46608

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in WPDO DoLogin Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DoLogin Security: from n/a through 3.7.1.
0
Attacker Value
Unknown

CVE-2023-46188

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Freesoul Deactivate Plugins – Plugin manager and cleanup: from n/a through 2.1.3.
0
Attacker Value
Unknown

CVE-2024-12595

Disclosure Date: January 02, 2025 (last updated January 02, 2025)
The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
0
Attacker Value
Unknown

CVE-2024-49694

Disclosure Date: December 31, 2024 (last updated January 02, 2025)
Missing Authorization vulnerability in imw3 My Wp Brand – Hide menu & Hide Plugin.This issue affects My Wp Brand – Hide menu & Hide Plugin: from n/a through 1.1.2.
0