Show filters
2,404 Total Results
Displaying 311-320 of 2,404
Sort by:
Attacker Value
Unknown

CVE-2024-5671

Disclosure Date: June 14, 2024 (last updated February 26, 2025)
Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.
0
Attacker Value
Unknown

CVE-2024-1295

Disclosure Date: June 14, 2024 (last updated February 26, 2025)
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)
Attacker Value
Unknown

CVE-2023-51377

Disclosure Date: June 14, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.
Attacker Value
Unknown

CVE-2024-28964

Disclosure Date: June 12, 2024 (last updated February 26, 2025)
Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue requires a victim to open a malicious file.
Attacker Value
Unknown

CVE-2024-3492

Disclosure Date: June 12, 2024 (last updated February 26, 2025)
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-4669

Disclosure Date: June 11, 2024 (last updated January 05, 2025)
The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Basic Slider, Upcoming Events, and Schedule widgets in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2024-35213

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process.
0
Attacker Value
Unknown

CVE-2024-31275

Disclosure Date: June 09, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.
Attacker Value
Unknown

CVE-2024-32824

Disclosure Date: June 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Evergreen Content Poster.This issue affects Evergreen Content Poster: from n/a through 1.4.2.
Attacker Value
Unknown

CVE-2024-30515

Disclosure Date: June 09, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.