Show filters
561 Total Results
Displaying 31-40 of 561
Sort by:
Attacker Value
Unknown

CVE-2024-51934

Disclosure Date: November 19, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uri Lazcano (Urielink) Ekiline Block Collection allows DOM-Based XSS.This issue affects Ekiline Block Collection: from n/a through 1.0.5.
0
Attacker Value
Unknown

CVE-2024-51893

Disclosure Date: November 19, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeAtelier Postify: Post Layout For Elementor allows DOM-Based XSS.This issue affects Postify: Post Layout For Elementor: from n/a through 1.0.1.
0
Attacker Value
Unknown

CVE-2024-52926

Disclosure Date: November 18, 2024 (last updated February 27, 2025)
Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
0
Attacker Value
Unknown

CVE-2024-50968

Disclosure Date: November 14, 2024 (last updated November 16, 2024)
A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout.
Attacker Value
Unknown

CVE-2024-10345

Disclosure Date: November 11, 2024 (last updated February 27, 2025)
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.
0
Attacker Value
Unknown

CVE-2024-10344

Disclosure Date: November 11, 2024 (last updated February 27, 2025)
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek.
0
Attacker Value
Unknown

CVE-2024-10314

Disclosure Date: November 11, 2024 (last updated February 27, 2025)
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek.
0
Attacker Value
Unknown

CVE-2024-51676

Disclosure Date: November 09, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Delicious Delisho allows Reflected XSS.This issue affects Delisho: from n/a through 1.0.6.
0
Attacker Value
Unknown

CVE-2024-10114

Disclosure Date: November 05, 2024 (last updated February 27, 2025)
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.
Attacker Value
Unknown

CVE-2024-43314

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through 1.3.9.3.