Show filters
10,200 Total Results
Displaying 331-340 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-32732

Disclosure Date: December 10, 2024 (last updated February 27, 2025)
Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the application.
0
Attacker Value
Unknown

CVE-2024-53847

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. Users should upgrade to Trix editor version 2.1.9 or 1.3.3, which uses DOMPurify to sanitize the pasted content.
0
Attacker Value
Unknown

CVE-2024-43222

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in SeventhQueen Sweet Date.This issue affects Sweet Date: from n/a through 3.7.3.
0
Attacker Value
Unknown

CVE-2023-50887

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in UserFeedback Team User Feedback allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through 1.0.10.
0
Attacker Value
Unknown

CVE-2023-47832

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in searchiq SearchIQ allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through 4.4.
0
Attacker Value
Unknown

CVE-2023-31073

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0.
0
Attacker Value
Unknown

CVE-2023-30488

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7.
0
Attacker Value
Unknown

CVE-2023-25703

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Meta slider and carousel with lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta slider and carousel with lightbox: from n/a through 1.6.2.
0
Attacker Value
Unknown

CVE-2023-25060

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Album and Image Gallery plus Lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Album and Image Gallery plus Lightbox: from n/a through 1.6.2.
0
Attacker Value
Unknown

CVE-2024-11464

Disclosure Date: December 07, 2024 (last updated February 27, 2025)
The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.