Show filters
9,960 Total Results
Displaying 311-320 of 9,960
Sort by:
Attacker Value
Unknown

CVE-2025-22508

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Roninwp FAT Event Lite allows PHP Local File Inclusion.This issue affects FAT Event Lite: from n/a through 1.1.
0
Attacker Value
Unknown

CVE-2024-12249

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings() function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's CSS settings.
Attacker Value
Unknown

CVE-2024-12218

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2025-0347

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php of the component Login. The manipulation of the argument u_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-13153

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: Since the widget code isn't part of the code, to apply the patch, the affected widgets: Image Tooltip, Notification, Simple Popup, Video Play Button, and Card Carousel, must be deleted and reinstalled manually.
Attacker Value
Unknown

CVE-2024-12802

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.
0
Attacker Value
Unknown

CVE-2024-40765

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
0
Attacker Value
Unknown

CVE-2024-12806

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
0
Attacker Value
Unknown

CVE-2024-12805

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
0
Attacker Value
Unknown

CVE-2024-12803

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
0