Show filters
1,013 Total Results
Displaying 31-40 of 1,013
Sort by:
Attacker Value
Unknown

CVE-2023-25060

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Album and Image Gallery plus Lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Album and Image Gallery plus Lightbox: from n/a through 1.6.2.
0
Attacker Value
Unknown

CVE-2024-12360

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as critical. This issue affects some unknown processing of the file class_update.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-53808

Disclosure Date: December 06, 2024 (last updated January 23, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8.
Attacker Value
Unknown

CVE-2024-53797

Disclosure Date: December 06, 2024 (last updated February 01, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue affects Beaver Builder: from n/a through 2.8.4.3.
Attacker Value
Unknown

CVE-2024-52458

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Templines TM Islamic Helper allows Reflected XSS.This issue affects TM Islamic Helper: from n/a through 1.0.1.
0
Attacker Value
Unknown

CVE-2024-50430

Disclosure Date: November 19, 2024 (last updated February 01, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue affects Beaver Builder: from n/a through 2.8.3.7.
Attacker Value
Unknown

CVE-2024-52426

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Linear Oy Linear linear allows DOM-Based XSS.This issue affects Linear: from n/a through 2.7.11.
Attacker Value
Unknown

CVE-2024-52926

Disclosure Date: November 18, 2024 (last updated December 24, 2024)
Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
0
Attacker Value
Unknown

CVE-2024-51628

Disclosure Date: November 09, 2024 (last updated November 10, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EzyOnlineBookings EzyOnlineBookings Online Booking System Widget allows DOM-Based XSS.This issue affects EzyOnlineBookings Online Booking System Widget: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2024-51620

Disclosure Date: November 09, 2024 (last updated November 09, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porsline allows Blind SQL Injection.This issue affects Porsline: from n/a through 1.0.2.
0