Show filters
5,941 Total Results
Displaying 371-380 of 5,941
Sort by:
Attacker Value
Unknown

CVE-2024-42658

Disclosure Date: August 19, 2024 (last updated February 26, 2025)
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
Attacker Value
Unknown

CVE-2024-42657

Disclosure Date: August 19, 2024 (last updated February 26, 2025)
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process
Attacker Value
Unknown

CVE-2024-7868

Disclosure Date: August 15, 2024 (last updated February 26, 2025)
In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
Attacker Value
Unknown

CVE-2024-7867

Disclosure Date: August 15, 2024 (last updated February 26, 2025)
In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
Attacker Value
Unknown

CVE-2024-7866

Disclosure Date: August 15, 2024 (last updated February 26, 2025)
In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
Attacker Value
Unknown

CVE-2024-7811

Disclosure Date: August 15, 2024 (last updated February 26, 2025)
A vulnerability classified as critical has been found in SourceCodester Daily Expenses Monitoring App 1.0. This affects an unknown part of the file /endpoint/delete-expense.php. The manipulation of the argument expense leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-38787

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
0
Attacker Value
Unknown

CVE-2024-42374

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve information from the SAP ADS system and exhaust the number of XMLForm service which makes the SAP ADS rendering (PDF creation) unavailable. This affects the confidentiality and availability of the application.
Attacker Value
Unknown

CVE-2024-43150

Disclosure Date: August 12, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS.This issue affects Xpro Elementor Addons: from n/a through 1.4.4.2.
0
Attacker Value
Unknown

CVE-2024-43127

Disclosure Date: August 12, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPFactory Products, Order & Customers Export for WooCommerce allows Reflected XSS.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.11.
0