Show filters
5,938 Total Results
Displaying 331-340 of 5,938
Sort by:
Attacker Value
Unknown
CVE-2024-45296
Disclosure Date: September 09, 2024 (last updated February 26, 2025)
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.
0
Attacker Value
Unknown
CVE-2024-7620
Disclosure Date: September 07, 2024 (last updated February 26, 2025)
The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions up to, and including, 0.9.7. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: This vulnerability is only exploitable when used in conjunction with a race condition as the uploaded file is deleted shortly after it is created.
0
Attacker Value
Unknown
CVE-2024-20497
Disclosure Date: September 04, 2024 (last updated February 26, 2025)
A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system.
This vulnerability is due to inadequate authorization checks for Mobile and Remote Access (MRA) users. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the attacker to intercept calls that are destined for a particular phone number or to make phone calls and have that phone number appear on the caller ID. To successfully exploit this vulnerability, the attacker must be an MRA user on an affected system.
0
Attacker Value
Unknown
CVE-2024-8380
Disclosure Date: September 03, 2024 (last updated February 26, 2025)
A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing of the file /endpoint/delete-account.php of the component Delete Contact Handler. The manipulation of the argument contact leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-8004
Disclosure Date: September 02, 2024 (last updated February 26, 2025)
A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
0
Attacker Value
Unknown
CVE-2024-7939
Disclosure Date: September 02, 2024 (last updated February 26, 2025)
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
0
Attacker Value
Unknown
CVE-2024-7938
Disclosure Date: September 02, 2024 (last updated February 26, 2025)
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
0
Attacker Value
Unknown
CVE-2024-7932
Disclosure Date: September 02, 2024 (last updated February 26, 2025)
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
0
Attacker Value
Unknown
CVE-2024-33051
Disclosure Date: September 02, 2024 (last updated February 26, 2025)
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
0
Attacker Value
Unknown
CVE-2024-33047
Disclosure Date: September 02, 2024 (last updated February 26, 2025)
Memory corruption when the captureRead QDCM command is invoked from user-space.
0