Show filters
614 Total Results
Displaying 31-40 of 614
Sort by:
Attacker Value
Unknown

CVE-2024-43967

Disclosure Date: August 26, 2024 (last updated September 19, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Widget: from n/a through 3.1.
Attacker Value
Unknown

CVE-2024-43966

Disclosure Date: August 26, 2024 (last updated September 14, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.
Attacker Value
Unknown

CVE-2024-7390

Disclosure Date: August 21, 2024 (last updated September 28, 2024)
The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to change the order of testimonials.
Attacker Value
Unknown

CVE-2024-7574

Disclosure Date: August 12, 2024 (last updated August 13, 2024)
The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing nonce validation on the 'options' function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-22169

Disclosure Date: August 02, 2024 (last updated August 03, 2024)
WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution within WD Discovery application's context. WD Discovery version 5.0.589 addresses this issue by disabling certain features and fuses in Electron. The attack vector for this issue requires the victim to have the WD Discovery app installed on their device.
0
Attacker Value
Unknown

CVE-2024-7323

Disclosure Date: August 02, 2024 (last updated September 12, 2024)
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .
Attacker Value
Unknown

CVE-2024-23091

Disclosure Date: July 30, 2024 (last updated August 24, 2024)
Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.
Attacker Value
Unknown

CVE-2024-22168

Disclosure Date: June 24, 2024 (last updated June 25, 2024)
A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the user’s browser session to carry out malicious activities.The web apps for these devices have been automatically updated to resolve this vulnerability and improve the security of your devices and data.
0
Attacker Value
Unknown

CVE-2023-49852

Disclosure Date: June 04, 2024 (last updated June 05, 2024)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through 1.4.
0
Attacker Value
Unknown

CVE-2024-5311

Disclosure Date: June 03, 2024 (last updated January 05, 2025)
DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.
0