Show filters
5,938 Total Results
Displaying 281-290 of 5,938
Sort by:
Attacker Value
Unknown

CVE-2024-10828

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.5 via deserialization of untrusted input during Order export when the "Try to convert serialized values" option is enabled. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Attacker Value
Unknown

CVE-2024-49524

Disclosure Date: November 07, 2024 (last updated February 27, 2025)
Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run when the page is rendered. This type of attack requires user interaction, as the victim would need to access a manipulated URL or provide specific input to trigger the vulnerability.
Attacker Value
Unknown

CVE-2024-49523

Disclosure Date: November 07, 2024 (last updated February 27, 2025)
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Attacker Value
Unknown

CVE-2024-10319

Disclosure Date: November 05, 2024 (last updated February 27, 2025)
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the render function in widgets/content-toggle/layout/frontend.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Attacker Value
Unknown

CVE-2024-38410

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
Attacker Value
Unknown

CVE-2024-38409

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Memory corruption while station LL statistic handling.
Attacker Value
Unknown

CVE-2024-38408

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Attacker Value
Unknown

CVE-2024-38407

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
Attacker Value
Unknown

CVE-2024-38406

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
Attacker Value
Unknown

CVE-2024-38403

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Transient DOS while parsing BTM ML IE when per STA profile is not included.