Show filters
410 Total Results
Displaying 31-40 of 410
Sort by:
Attacker Value
Unknown

CVE-2024-10583

Disclosure Date: December 12, 2024 (last updated February 27, 2025)
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in all versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-54008

Disclosure Date: December 10, 2024 (last updated February 27, 2025)
An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host.
0
Attacker Value
Unknown

CVE-2024-53672

Disclosure Date: December 03, 2024 (last updated February 27, 2025)
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.
0
Attacker Value
Unknown

CVE-2024-51773

Disclosure Date: December 03, 2024 (last updated February 27, 2025)
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the user is authorized to do, including accessing the user's data and altering information within the user's permissions. This could lead to data modification, deletion, or theft, including unauthorized access to files, file deletion, or the theft of session cookies, which an attacker could use to hijack a user's session.
0
Attacker Value
Unknown

CVE-2024-51772

Disclosure Date: December 03, 2024 (last updated February 27, 2025)
An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
0
Attacker Value
Unknown

CVE-2024-51771

Disclosure Date: December 03, 2024 (last updated February 27, 2025)
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system.
0
Attacker Value
Unknown

CVE-2024-11856

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.
0
Attacker Value
Unknown

CVE-2024-11685

Disclosure Date: November 28, 2024 (last updated February 27, 2025)
The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can successfully trick a user into performing an action, such as clicking on a specially crafted link.
Attacker Value
Unknown

CVE-2024-11684

Disclosure Date: November 28, 2024 (last updated February 27, 2025)
The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-51766

Disclosure Date: November 22, 2024 (last updated February 27, 2025)
A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series.
0