Show filters
8,317 Total Results
Displaying 201-210 of 8,317
Sort by:
Attacker Value
Unknown
CVE-2024-11459
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
The Country Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-11419
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the get3_init_admin_page() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-28141
Disclosure Date: December 11, 2024 (last updated December 21, 2024)
The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they visit an attacker-controlled website or click on a malicious link. E.g. an attacker can forge malicious links to reset the admin password or create new users.
0
Attacker Value
Unknown
CVE-2024-28140
Disclosure Date: December 11, 2024 (last updated December 21, 2024)
The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running "ps aux" as the root user and observing the output.
0
Attacker Value
Unknown
CVE-2024-28139
Disclosure Date: December 11, 2024 (last updated December 21, 2024)
The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.
0
Attacker Value
Unknown
CVE-2024-47946
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PHP content can be uploaded as desktop backgrounds or lock screens. After the upload, the PHP script is available in the web root. The PHP code executes once the uploaded file is accessed. This allows the execution of arbitrary PHP code and OS commands on the device as "www-data".
0
Attacker Value
Unknown
CVE-2024-28138
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user. The HTTP GET parameter "data" is not properly sanitized.
0
Attacker Value
Unknown
CVE-2024-52391
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.
0
Attacker Value
Unknown
CVE-2024-54226
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Karl Kiesinger Country Blocker allows Stored XSS.This issue affects Country Blocker: from n/a through 3.2.
0
Attacker Value
Unknown
CVE-2024-54225
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodegearThemes Designer allows PHP Local File Inclusion.This issue affects Designer: from n/a through 1.3.3.
0