Show filters
985 Total Results
Displaying 31-40 of 985
Sort by:
Attacker Value
Unknown

CVE-2024-54197

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and confidentiality of data. It has no impact on availability of the application.
0
Attacker Value
Unknown

CVE-2024-45761

Disclosure Date: December 09, 2024 (last updated February 05, 2025)
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or Denial of Service.
Attacker Value
Unknown

CVE-2024-45760

Disclosure Date: December 09, 2024 (last updated February 05, 2025)
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.
Attacker Value
Unknown

CVE-2024-54227

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in theDotstore Minimum and Maximum Quantity for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Minimum and Maximum Quantity for WooCommerce: from n/a through 2.0.0.
0
Attacker Value
Unknown

CVE-2023-47776

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in miniOrange miniorange otp verification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects miniorange otp verification: from n/a through 4.2.1.
0
Attacker Value
Unknown

CVE-2023-47694

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in appsbd Mini Cart Drawer For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mini Cart Drawer For WooCommerce: from n/a through 4.0.0.
0
Attacker Value
Unknown

CVE-2024-11380

Disclosure Date: December 07, 2024 (last updated December 21, 2024)
The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortcode in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-52765

Disclosure Date: November 20, 2024 (last updated December 21, 2024)
H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.
Attacker Value
Unknown

CVE-2024-51895

Disclosure Date: November 19, 2024 (last updated November 20, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Minical Minical Hotel Booking Plugin allows Stored XSS.This issue affects Minical Hotel Booking Plugin: from n/a through 1.0.2.
0
Attacker Value
Unknown

CVE-2024-52383

Disclosure Date: November 14, 2024 (last updated November 15, 2024)
Missing Authorization vulnerability in KCT Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One: from n/a through 2.1.2.
0