Show filters
375 Total Results
Displaying 31-40 of 375
Sort by:
Attacker Value
Unknown

CVE-2021-42305

Disclosure Date: November 10, 2021 (last updated November 28, 2024)
Microsoft Exchange Server Spoofing Vulnerability
1
Attacker Value
Very High

CVE-2018-8302

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
0
Attacker Value
Unknown

CVE-2024-13692

Disclosure Date: February 14, 2025 (last updated February 14, 2025)
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite linked refund image attachments, overwrite refund request message, overwrite order messages, and read order messages of other users.
Attacker Value
Unknown

CVE-2024-13641

Disclosure Date: February 14, 2025 (last updated February 14, 2025)
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/attachment directory which can contain file attachments for order refunds.
Attacker Value
Unknown

CVE-2024-13487

Disclosure Date: February 06, 2025 (last updated February 07, 2025)
The The CURCY – Multi Currency for WooCommerce – The best free currency exchange plugin – Run smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution via the get_products_price() function in all versions up to, and including, 2.2.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
0
Attacker Value
Unknown

CVE-2024-54332

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates allows Stored XSS.This issue affects WP Currency Exchange Rates: from n/a through 1.2.0.
0
Attacker Value
Unknown

CVE-2024-11969

Disclosure Date: November 28, 2024 (last updated December 21, 2024)
The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified that full control permissions exist on the ‘Everyone’ group (i.e. any user who has local access to the operating system regardless of their privileges).
0
Attacker Value
Unknown

CVE-2024-7130

Disclosure Date: November 21, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Computer KION Exchange Programs Software allows Reflected XSS.This issue affects KION Exchange Programs Software: before 1.21.9092.29966.
0
Attacker Value
Unknown

CVE-2024-49040

Disclosure Date: November 12, 2024 (last updated November 27, 2024)
Microsoft Exchange Server Spoofing Vulnerability
Attacker Value
Unknown

CVE-2024-9459

Disclosure Date: November 05, 2024 (last updated November 07, 2024)
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.