Show filters
614 Total Results
Displaying 31-40 of 614
Sort by:
Attacker Value
Unknown
CVE-2024-43967
Disclosure Date: August 26, 2024 (last updated September 19, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Widget: from n/a through 3.1.
0
Attacker Value
Unknown
CVE-2024-43966
Disclosure Date: August 26, 2024 (last updated September 14, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.
0
Attacker Value
Unknown
CVE-2024-7390
Disclosure Date: August 21, 2024 (last updated September 28, 2024)
The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to change the order of testimonials.
0
Attacker Value
Unknown
CVE-2024-7574
Disclosure Date: August 12, 2024 (last updated August 13, 2024)
The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing nonce validation on the 'options' function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-22169
Disclosure Date: August 02, 2024 (last updated August 03, 2024)
WD Discovery
versions prior to 5.0.589 contain a misconfiguration in the Node.js environment
settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable.
Any malicious application operating with standard user permissions can exploit
this vulnerability, enabling code execution within WD Discovery application's
context. WD Discovery version 5.0.589 addresses this issue by disabling certain
features and fuses in Electron. The attack vector for this issue requires the victim to have the WD Discovery app installed on their device.
0
Attacker Value
Unknown
CVE-2024-7323
Disclosure Date: August 02, 2024 (last updated September 12, 2024)
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .
0
Attacker Value
Unknown
CVE-2024-23091
Disclosure Date: July 30, 2024 (last updated August 24, 2024)
Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.
0
Attacker Value
Unknown
CVE-2024-22168
Disclosure Date: June 24, 2024 (last updated June 25, 2024)
A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the user’s browser session to carry out malicious activities.The web apps for these devices have been automatically updated to resolve this vulnerability and improve the security of your devices and data.
0
Attacker Value
Unknown
CVE-2023-49852
Disclosure Date: June 04, 2024 (last updated June 05, 2024)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through 1.4.
0
Attacker Value
Unknown
CVE-2024-5311
Disclosure Date: June 03, 2024 (last updated January 05, 2025)
DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.
0