Show filters
2,296 Total Results
Displaying 41-50 of 2,296
Sort by:
Attacker Value
Unknown

CVE-2024-13589

Disclosure Date: February 19, 2025 (last updated February 27, 2025)
The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-12314

Disclosure Date: February 18, 2025 (last updated February 25, 2025)
The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This is due to plugin storing HTTP headers in the cached data. This makes it possible for unauthenticated attackers to poison the cache with custom HTTP headers that may be unsanitized which can lead to Cross-Site Scripting.
0
Attacker Value
Unknown

CVE-2024-56180

Disclosure Date: February 14, 2025 (last updated February 27, 2025)
CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under the master branch in project repo or version 1.11.0 to fix this issue.
0
Attacker Value
Unknown

CVE-2024-52577

Disclosure Date: February 14, 2025 (last updated February 27, 2025)
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose class is present in the Ignite server classpath and sends it to Ignite server endpoints. Deserialization of such a message by the Ignite server may result in the execution of arbitrary code on the Apache Ignite server side.
0
Attacker Value
Unknown

CVE-2025-1247

Disclosure Date: February 13, 2025 (last updated February 28, 2025)
A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.
0
Attacker Value
Unknown

CVE-2024-46910

Disclosure Date: February 13, 2025 (last updated February 27, 2025)
An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-32838

Disclosure Date: February 12, 2025 (last updated February 27, 2025)
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API endpoints' query parameter.  Users are recommended to upgrade to version 1.10.1, which fixes this issue. A SQL Validator has been implemented which allows us to configure a series of tests and checks against our SQL queries that will allow us to validate and protect against nearly all potential SQL injection attacks.
0
Attacker Value
Unknown

CVE-2024-32838

Disclosure Date: February 12, 2025 (last updated February 27, 2025)
SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API endpoints' query parameter.  Users are recommended to upgrade to version 1.10.1, which fixes this issue. A SQL Validator has been implemented which allows us to configure a series of tests and checks against our SQL queries that will allow us to validate and protect against nearly all potential SQL injection attacks.
0
Attacker Value
Unknown

CVE-2025-21188

Disclosure Date: February 11, 2025 (last updated March 01, 2025)
Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2025-0862

Disclosure Date: February 11, 2025 (last updated February 27, 2025)
The SuperSaaS – online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘after’ parameter in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is limited to Chromium-based browsers (e.g. Chrome, Edge, Brave).