Show filters
797 Total Results
Displaying 31-40 of 797
Sort by:
Attacker Value
Unknown

CVE-2024-52456

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPoets Awesome Studio allows Reflected XSS.This issue affects Awesome Studio: from n/a through 2.4.4.
0
Attacker Value
Unknown

CVE-2024-49038

Disclosure Date: November 26, 2024 (last updated January 13, 2025)
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.
Attacker Value
Unknown

CVE-2024-10873

Disclosure Date: November 23, 2024 (last updated January 05, 2025)
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
0
Attacker Value
Unknown

CVE-2024-49044

Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Visual Studio Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-43499

Disclosure Date: November 12, 2024 (last updated November 20, 2024)
.NET and Visual Studio Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2024-43498

Disclosure Date: November 12, 2024 (last updated November 20, 2024)
.NET and Visual Studio Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-1932

Disclosure Date: November 07, 2024 (last updated November 07, 2024)
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2024-9579

Disclosure Date: November 05, 2024 (last updated November 09, 2024)
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
Attacker Value
Unknown

CVE-2024-48870

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.
Attacker Value
Unknown

CVE-2024-47801

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.