Show filters
1,460 Total Results
Displaying 31-40 of 1,460
Sort by:
Attacker Value
Unknown

CVE-2024-13186

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
0
Attacker Value
Unknown

CVE-2024-13185

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
0
Attacker Value
Unknown

CVE-2024-10585

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.
Attacker Value
Unknown

CVE-2024-56291

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Deserialization of Untrusted Data vulnerability in plainware.com PlainInventory allows Object Injection.This issue affects PlainInventory: from n/a through 3.1.6.
0
Attacker Value
Unknown

CVE-2024-11627

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
0
Attacker Value
Unknown

CVE-2024-11626

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
0
Attacker Value
Unknown

CVE-2024-11625

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
0
Attacker Value
Unknown

CVE-2024-11984

Disclosure Date: December 19, 2024 (last updated December 19, 2024)
A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file.
0
Attacker Value
Unknown

CVE-2024-55949

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.
0
Attacker Value
Unknown

CVE-2024-54306

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in KCT AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot allows Cross Site Request Forgery.This issue affects AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot: from n/a through 1.6.2.
0