Show filters
6,773 Total Results
Displaying 361-370 of 6,773
Sort by:
Attacker Value
Unknown

CVE-2024-52382

Disclosure Date: November 14, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Medma Technologies Matix Popup Builder allows Privilege Escalation.This issue affects Matix Popup Builder: from n/a through 1.0.0.
0
Attacker Value
Unknown

CVE-2024-47915

Disclosure Date: November 14, 2024 (last updated February 27, 2025)
VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
0
Attacker Value
Unknown

CVE-2024-47914

Disclosure Date: November 14, 2024 (last updated February 27, 2025)
VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)
0
Attacker Value
Unknown

CVE-2024-45254

Disclosure Date: November 14, 2024 (last updated February 27, 2025)
VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown

CVE-2024-10013

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.
Attacker Value
Unknown

CVE-2024-10012

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.
Attacker Value
Unknown

CVE-2024-10794

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.6 via the 'bhf' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created via Elementor that they should not have access to.
Attacker Value
Unknown

CVE-2024-10593

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validation on the process_admin_ui function. This makes it possible for unauthenticated attackers to delete WPForm logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-10778

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts crated by Elementor that they should not have access to.
Attacker Value
Unknown

CVE-2024-51722

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
A local privilege escalation vulnerability in the SecuSUITE Server (System Configuration) of SecuSUITE versions 5.0.420 and earlier could allow a successful attacker that had gained control of code running under one of the system accounts listed in the configuration file to potentially issue privileged script commands.
0