Show filters
285 Total Results
Displaying 31-40 of 285
Sort by:
Attacker Value
Unknown
CVE-2024-49298
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice allows Stored XSS.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.6.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-10018
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.
0
Attacker Value
Unknown
CVE-2024-8560
Disclosure Date: September 07, 2024 (last updated September 11, 2024)
A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashier/total_amount/discount_percentage/discount_amount/tendered_amount leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-43941
Disclosure Date: August 29, 2024 (last updated September 05, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Propovoice Propovoice Pro allows SQL Injection.This issue affects Propovoice Pro: from n/a through 1.7.0.3.
0
Attacker Value
Unknown
CVE-2023-7260
Disclosure Date: August 22, 2024 (last updated October 17, 2024)
Path Traversal vulnerability discovered in OpenText™ CX-E Voice,
affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.
0
Attacker Value
Unknown
CVE-2024-43350
Disclosure Date: August 18, 2024 (last updated August 19, 2024)
Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6.4.
0
Attacker Value
Unknown
CVE-2024-36446
Disclosure Date: August 13, 2024 (last updated September 13, 2024)
The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema.
0
Attacker Value
Unknown
CVE-2024-5172
Disclosure Date: June 18, 2024 (last updated July 06, 2024)
The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2024-30517
Disclosure Date: June 09, 2024 (last updated October 08, 2024)
Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2.
0