Show filters
914 Total Results
Displaying 231-240 of 914
Sort by:
Attacker Value
Unknown

CVE-2024-1122

Disclosure Date: February 09, 2024 (last updated February 26, 2025)
The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export event data.
Attacker Value
Unknown

CVE-2023-6557

Disclosure Date: February 05, 2024 (last updated October 08, 2024)
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles and IDs of pending, private and draft posts.
Attacker Value
Unknown

CVE-2023-52118

Disclosure Date: February 01, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP User Profile Avatar allows Stored XSS.This issue affects WP User Profile Avatar: from n/a through 1.0.
Attacker Value
Unknown

CVE-2023-7200

Disclosure Date: January 29, 2024 (last updated February 26, 2025)
The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-7170

Disclosure Date: January 22, 2024 (last updated February 26, 2025)
The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-6447

Disclosure Date: January 22, 2024 (last updated February 26, 2025)
The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.
Attacker Value
Unknown

CVE-2023-38541

Disclosure Date: January 19, 2024 (last updated February 26, 2025)
Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-50950

Disclosure Date: January 17, 2024 (last updated February 26, 2025)
IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM X-Force ID: 275709.
Attacker Value
Unknown

CVE-2024-0238

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.
Attacker Value
Unknown

CVE-2024-0237

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc