Show filters
5,941 Total Results
Displaying 371-380 of 5,941
Sort by:
Attacker Value
Unknown
CVE-2024-42658
Disclosure Date: August 19, 2024 (last updated February 26, 2025)
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
0
Attacker Value
Unknown
CVE-2024-42657
Disclosure Date: August 19, 2024 (last updated February 26, 2025)
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process
0
Attacker Value
Unknown
CVE-2024-7868
Disclosure Date: August 15, 2024 (last updated February 26, 2025)
In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
0
Attacker Value
Unknown
CVE-2024-7867
Disclosure Date: August 15, 2024 (last updated February 26, 2025)
In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
0
Attacker Value
Unknown
CVE-2024-7866
Disclosure Date: August 15, 2024 (last updated February 26, 2025)
In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
0
Attacker Value
Unknown
CVE-2024-7811
Disclosure Date: August 15, 2024 (last updated February 26, 2025)
A vulnerability classified as critical has been found in SourceCodester Daily Expenses Monitoring App 1.0. This affects an unknown part of the file /endpoint/delete-expense.php. The manipulation of the argument expense leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-38787
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
0
Attacker Value
Unknown
CVE-2024-42374
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
BEx Web Java Runtime Export Web Service does not
sufficiently validate an XML document accepted from an untrusted source. An
attacker can retrieve information from the SAP ADS system and exhaust the
number of XMLForm service which makes the SAP ADS rendering (PDF creation)
unavailable. This affects the confidentiality and availability of the
application.
0
Attacker Value
Unknown
CVE-2024-43150
Disclosure Date: August 12, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS.This issue affects Xpro Elementor Addons: from n/a through 1.4.4.2.
0
Attacker Value
Unknown
CVE-2024-43127
Disclosure Date: August 12, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPFactory Products, Order & Customers Export for WooCommerce allows Reflected XSS.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.11.
0