Show filters
561 Total Results
Displaying 41-50 of 561
Sort by:
Attacker Value
Unknown

CVE-2024-39650

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouchers: from n/a through 4.9.4.
0
Attacker Value
Unknown

CVE-2024-50460

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FirelightWP Firelight Lightbox allows Stored XSS.This issue affects Firelight Lightbox: from n/a through 2.3.3.
Attacker Value
Unknown

CVE-2024-10180

Disclosure Date: October 24, 2024 (last updated February 26, 2025)
The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's field_group shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-48033

Disclosure Date: October 11, 2024 (last updated February 26, 2025)
Deserialization of Untrusted Data vulnerability in Elie Burstein, Baptiste Gourdin Talkback allows Object Injection.This issue affects Talkback: from n/a through 1.0.
0
Attacker Value
Unknown

CVE-2024-7206

Disclosure Date: October 08, 2024 (last updated February 26, 2025)
SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware
0
Attacker Value
Unknown

CVE-2024-8481

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.2. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2024-8497

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.
0
Attacker Value
Unknown

CVE-2024-8067

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified.
0
Attacker Value
Unknown

CVE-2024-45373

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.