Show filters
203 Total Results
Displaying 31-40 of 203
Sort by:
Attacker Value
Unknown

CVE-2024-24759

Disclosure Date: September 05, 2024 (last updated September 07, 2024)
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.
Attacker Value
Unknown

CVE-2024-43149

Disclosure Date: August 12, 2024 (last updated August 13, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through 4.3.7.
0
Attacker Value
Unknown

CVE-2024-43360

Disclosure Date: August 12, 2024 (last updated September 05, 2024)
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.
Attacker Value
Unknown

CVE-2024-43359

Disclosure Date: August 12, 2024 (last updated September 05, 2024)
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montagereview via the displayinterval, speed, and scale parameters. This vulnerability is fixed in 1.36.34 and 1.37.61.
Attacker Value
Unknown

CVE-2024-43358

Disclosure Date: August 12, 2024 (last updated September 05, 2024)
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the filter view via the filter[Id]. This vulnerability is fixed in 1.36.34 and 1.37.61.
Attacker Value
Unknown

CVE-2023-41884

Disclosure Date: August 12, 2024 (last updated September 14, 2024)
ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34.
Attacker Value
Unknown

CVE-2024-5004

Disclosure Date: July 22, 2024 (last updated July 26, 2024)
The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2024-29078

Disclosure Date: May 28, 2024 (last updated May 28, 2024)
Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated attacker with access to the product to alter the product settings.
0
Attacker Value
Unknown

CVE-2024-28880

Disclosure Date: May 28, 2024 (last updated May 28, 2024)
Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the product to obtain sensitive information of the product.
0
Attacker Value
Unknown

CVE-2024-4086

Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The CM Tooltip Glossary – Powerful Glossary Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.11. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthenticated attackers to change the plugin's settings or reset them via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0