Show filters
492 Total Results
Displaying 31-40 of 492
Sort by:
Attacker Value
Unknown

CVE-2024-6117

Disclosure Date: August 05, 2024 (last updated August 31, 2024)
A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.
Attacker Value
Unknown

CVE-2024-38289

Disclosure Date: July 25, 2024 (last updated August 14, 2024)
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.
Attacker Value
Unknown

CVE-2024-38288

Disclosure Date: July 25, 2024 (last updated August 14, 2024)
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.
Attacker Value
Unknown

CVE-2024-38287

Disclosure Date: July 25, 2024 (last updated August 14, 2024)
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.
Attacker Value
Unknown

CVE-2024-22296

Disclosure Date: June 10, 2024 (last updated September 26, 2024)
Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28.
Attacker Value
Unknown

CVE-2024-35693

Disclosure Date: June 08, 2024 (last updated August 30, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Code for Recovery 12 Step Meeting List allows Reflected XSS.This issue affects 12 Step Meeting List: from n/a through 3.14.33.
Attacker Value
Unknown

CVE-2024-34816

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8.
0
Attacker Value
Unknown

CVE-2024-3275

Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.18 via the search_posts function. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain post excerpts including those of draft and pending posts.
0
Attacker Value
Unknown

CVE-2024-32795

Disclosure Date: April 24, 2024 (last updated April 25, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8.
0
Attacker Value
Unknown

CVE-2024-24699

Disclosure Date: February 14, 2024 (last updated October 05, 2024)
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.