Show filters
8,318 Total Results
Displaying 351-360 of 8,318
Sort by:
Attacker Value
Unknown

CVE-2024-10738

Disclosure Date: November 03, 2024 (last updated February 27, 2025)
A vulnerability classified as critical was found in itsourcecode Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file manage-breed.php. The manipulation of the argument breed leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-47302

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in WPManageNinja LLC Fluent Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through 1.8.0.
Attacker Value
Unknown

CVE-2024-43982

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Geek Code Lab Login As Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login As Users: from n/a through 1.4.3.
Attacker Value
Unknown

CVE-2024-43212

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.7.7.
0
Attacker Value
Unknown

CVE-2024-37277

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
Attacker Value
Unknown

CVE-2024-37218

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in WordPress Page Builder Sandwich Team Page Builder Sandwich – Front-End Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page Builder Sandwich – Front-End Page Builder: from n/a through 5.1.0.
0
Attacker Value
Unknown

CVE-2024-10609

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. This affects an unknown part of the file typeadd.php. The manipulation of the argument sex leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-10454

Disclosure Date: October 31, 2024 (last updated February 27, 2025)
Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to perform click hijacking on victims.
0
Attacker Value
Unknown

CVE-2024-25566

Disclosure Date: October 29, 2024 (last updated February 26, 2025)
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
Attacker Value
Unknown

CVE-2024-49769

Disclosure Date: October 29, 2024 (last updated February 26, 2025)
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitress won't correctly clean up the connection leading to the main thread attempting to write to a socket that no longer exists, but not removing it from the list of sockets to attempt to process. This leads to a busy-loop calling the write function. A remote attacker could run waitress out of available sockets with very little resources required. Waitress 3.0.1 contains fixes that remove the race condition.