Show filters
345 Total Results
Displaying 31-40 of 345
Sort by:
Attacker Value
Unknown

CVE-2024-45678

Disclosure Date: September 03, 2024 (last updated September 13, 2024)
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.
Attacker Value
Unknown

CVE-2024-3112

Disclosure Date: July 12, 2024 (last updated July 25, 2024)
The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Attacker Value
Unknown

CVE-2024-37486

Disclosure Date: July 09, 2024 (last updated August 03, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.
Attacker Value
Unknown

CVE-2024-34599

Disclosure Date: July 02, 2024 (last updated July 03, 2024)
Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.
Attacker Value
Unknown

CVE-2023-39990

Disclosure Date: June 19, 2024 (last updated January 25, 2025)
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
Attacker Value
Unknown

CVE-2023-40608

Disclosure Date: June 19, 2024 (last updated June 20, 2024)
Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3.
0
Attacker Value
Unknown

CVE-2024-1407

Disclosure Date: June 19, 2024 (last updated January 18, 2025)
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to subscribe to, modify, or cancel membership for a user via a forged request granted they can trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown

CVE-2024-5731

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination of a request by manipulating the parameter, thereby leveraging sensitive information.
0
Attacker Value
Unknown

CVE-2024-5671

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.
0
Attacker Value
Unknown

CVE-2024-20363

Disclosure Date: May 22, 2024 (last updated May 23, 2024)
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.
0