Show filters
5,938 Total Results
Displaying 321-330 of 5,938
Sort by:
Attacker Value
Unknown

CVE-2024-9266

Disclosure Date: October 03, 2024 (last updated February 26, 2025)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.
0
Attacker Value
Unknown

CVE-2024-8793

Disclosure Date: October 01, 2024 (last updated February 26, 2025)
The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.2.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-8771

Disclosure Date: September 26, 2024 (last updated February 26, 2025)
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including the content of private, password protected, pending, and draft posts and pages.
Attacker Value
Unknown

CVE-2024-20433

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow when processing crafted RSVP packets. An attacker could exploit this vulnerability by sending RSVP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Attacker Value
Unknown

CVE-2024-42861

Disclosure Date: September 23, 2024 (last updated October 01, 2024)
An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function
Attacker Value
Unknown

CVE-2024-46938

Disclosure Date: September 15, 2024 (last updated February 26, 2025)
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
Attacker Value
Unknown

CVE-2024-8533

Disclosure Date: September 12, 2024 (last updated February 26, 2025)
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.
Attacker Value
Unknown

CVE-2024-8306

Disclosure Date: September 11, 2024 (last updated February 26, 2025)
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.
Attacker Value
Unknown

CVE-2024-43796

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
Attacker Value
Unknown

CVE-2024-6596

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.