Show filters
3,125 Total Results
Displaying 201-210 of 3,125
Sort by:
Attacker Value
Unknown
CVE-2024-20405
Disclosure Date: June 05, 2024 (last updated February 26, 2025)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability.
This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.
0
Attacker Value
Unknown
CVE-2024-20404
Disclosure Date: June 05, 2024 (last updated February 26, 2025)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system.
This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.
0
Attacker Value
Unknown
CVE-2024-4532
Disclosure Date: May 27, 2024 (last updated February 26, 2025)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks
0
Attacker Value
Unknown
CVE-2024-4531
Disclosure Date: May 27, 2024 (last updated May 27, 2024)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks
0
Attacker Value
Unknown
CVE-2024-4530
Disclosure Date: May 27, 2024 (last updated May 27, 2024)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks
0
Attacker Value
Unknown
CVE-2024-4529
Disclosure Date: May 27, 2024 (last updated May 27, 2024)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks
0
Attacker Value
Unknown
CVE-2024-4443
Disclosure Date: May 22, 2024 (last updated January 05, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2024-3292
Disclosure Date: May 17, 2024 (last updated February 26, 2025)
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292
0
Attacker Value
Unknown
CVE-2024-3291
Disclosure Date: May 17, 2024 (last updated February 26, 2025)
When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
0
Attacker Value
Unknown
CVE-2024-3290
Disclosure Date: May 17, 2024 (last updated February 26, 2025)
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host
0