Show filters
9,280 Total Results
Displaying 301-310 of 9,280
Sort by:
Attacker Value
Unknown
CVE-2024-11768
Disclosure Date: December 19, 2024 (last updated February 27, 2025)
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
0
Attacker Value
Unknown
CVE-2024-11740
Disclosure Date: December 19, 2024 (last updated February 27, 2025)
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
0
Attacker Value
Unknown
CVE-2024-10548
Disclosure Date: December 19, 2024 (last updated February 27, 2025)
The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including the hashed passwords of project owners (e.g. adminstrators).
0
Attacker Value
Unknown
CVE-2024-54381
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in theDotstore Advance Menu Manager.This issue affects Advance Menu Manager: from n/a through 3.1.1.
0
Attacker Value
Unknown
CVE-2024-48889
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiManager Cloud version 7.4.4 and below, version 7.2.7 to 7.2.1, version 7.0.12 to 7.0.1 may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests.
0
Attacker Value
Unknown
CVE-2024-21546
Disclosure Date: December 18, 2024 (last updated February 27, 2025)
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.
0
Attacker Value
Unknown
CVE-2024-49820
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
0
Attacker Value
Unknown
CVE-2024-49819
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
0
Attacker Value
Unknown
CVE-2024-49818
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1
could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-49817
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
0