Show filters
985 Total Results
Displaying 41-50 of 985
Sort by:
Attacker Value
Unknown
CVE-2024-50524
Disclosure Date: November 09, 2024 (last updated November 09, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quyle91 Administrator Z allows Blind SQL Injection.This issue affects Administrator Z: from n/a through 2024.11.04.
0
Attacker Value
Unknown
CVE-2024-8959
Disclosure Date: October 24, 2024 (last updated January 06, 2025)
The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.0.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
0
Attacker Value
Unknown
CVE-2024-10202
Disclosure Date: October 21, 2024 (last updated October 25, 2024)
Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
0
Attacker Value
Unknown
CVE-2024-10201
Disclosure Date: October 21, 2024 (last updated October 25, 2024)
Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells.
0
Attacker Value
Unknown
CVE-2024-10200
Disclosure Date: October 21, 2024 (last updated October 25, 2024)
Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server.
0
Attacker Value
Unknown
CVE-2024-49314
Disclosure Date: October 17, 2024 (last updated January 05, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in 酱茄 JiangQie Free Mini Program allows Upload a Web Shell to a Web Server.This issue affects JiangQie Free Mini Program: from n/a through 2.5.2.
0
Attacker Value
Unknown
CVE-2024-9863
Disclosure Date: October 17, 2024 (last updated January 06, 2025)
The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-45276
Disclosure Date: October 15, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
0
Attacker Value
Unknown
CVE-2024-45275
Disclosure Date: October 15, 2024 (last updated October 18, 2024)
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
0