Show filters
6,774 Total Results
Displaying 261-270 of 6,774
Sort by:
Attacker Value
Unknown
CVE-2023-36531
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68.
0
Attacker Value
Unknown
CVE-2024-21577
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.
0
Attacker Value
Unknown
CVE-2024-21576
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and FindContour custom nodes. In the entrypoint function to each node, there’s a call to eval which can be triggered by generating a workflow that injects a crafted string into the node. This can result in executing arbitrary code on the server.
0
Attacker Value
Unknown
CVE-2024-11832
Disclosure Date: December 13, 2024 (last updated January 13, 2025)
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JavaScript row settings in all versions up to, and including, 2.8.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-21575
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in remote code execution (RCE).
0
Attacker Value
Unknown
CVE-2024-54101
Disclosure Date: December 12, 2024 (last updated January 18, 2025)
Denial of service (DoS) vulnerability in the installation module
Impact: Successful exploitation of this vulnerability will affect availability.
0
Attacker Value
Unknown
CVE-2024-54100
Disclosure Date: December 12, 2024 (last updated January 15, 2025)
Vulnerability of improper access control in the secure input module
Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
0
Attacker Value
Unknown
CVE-2024-54099
Disclosure Date: December 12, 2024 (last updated January 13, 2025)
File replacement vulnerability on some devices
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
0
Attacker Value
Unknown
CVE-2024-54098
Disclosure Date: December 12, 2024 (last updated January 13, 2025)
Service logic error vulnerability in the system service module
Impact: Successful exploitation of this vulnerability may affect service integrity.
0
Attacker Value
Unknown
CVE-2024-54097
Disclosure Date: December 12, 2024 (last updated January 13, 2025)
Security vulnerability in the HiView module
Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.
0