Show filters
6,774 Total Results
Displaying 261-270 of 6,774
Sort by:
Attacker Value
Unknown

CVE-2023-36531

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68.
0
Attacker Value
Unknown

CVE-2024-21577

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.
0
Attacker Value
Unknown

CVE-2024-21576

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and FindContour custom nodes. In the entrypoint function to each node, there’s a call to eval which can be triggered by generating a workflow that injects a crafted string into the node. This can result in executing arbitrary code on the server.
0
Attacker Value
Unknown

CVE-2024-11832

Disclosure Date: December 13, 2024 (last updated January 13, 2025)
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JavaScript row settings in all versions up to, and including, 2.8.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-21575

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in remote code execution (RCE).
0
Attacker Value
Unknown

CVE-2024-54101

Disclosure Date: December 12, 2024 (last updated January 18, 2025)
Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability will affect availability.
Attacker Value
Unknown

CVE-2024-54100

Disclosure Date: December 12, 2024 (last updated January 15, 2025)
Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Attacker Value
Unknown

CVE-2024-54099

Disclosure Date: December 12, 2024 (last updated January 13, 2025)
File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Attacker Value
Unknown

CVE-2024-54098

Disclosure Date: December 12, 2024 (last updated January 13, 2025)
Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.
Attacker Value
Unknown

CVE-2024-54097

Disclosure Date: December 12, 2024 (last updated January 13, 2025)
Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.