Show filters
797 Total Results
Displaying 31-40 of 797
Sort by:
Attacker Value
Unknown
CVE-2024-52456
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPoets Awesome Studio allows Reflected XSS.This issue affects Awesome Studio: from n/a through 2.4.4.
0
Attacker Value
Unknown
CVE-2024-49038
Disclosure Date: November 26, 2024 (last updated January 13, 2025)
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.
0
Attacker Value
Unknown
CVE-2024-10873
Disclosure Date: November 23, 2024 (last updated January 05, 2025)
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
0
Attacker Value
Unknown
CVE-2024-49044
Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Visual Studio Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-43499
Disclosure Date: November 12, 2024 (last updated November 20, 2024)
.NET and Visual Studio Denial of Service Vulnerability
0
Attacker Value
Unknown
CVE-2024-43498
Disclosure Date: November 12, 2024 (last updated November 20, 2024)
.NET and Visual Studio Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-1932
Disclosure Date: November 07, 2024 (last updated November 07, 2024)
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2024-9579
Disclosure Date: November 05, 2024 (last updated November 09, 2024)
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
0
Attacker Value
Unknown
CVE-2024-48870
Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability.
If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.
0
Attacker Value
Unknown
CVE-2024-47801
Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability.
Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
0