Show filters
461 Total Results
Displaying 41-50 of 461
Sort by:
Attacker Value
Unknown

CVE-2024-1371

Disclosure Date: April 30, 2024 (last updated April 30, 2024)
The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to delete arbitrary posts.
0
Attacker Value
Unknown

CVE-2024-0899

Disclosure Date: April 09, 2024 (last updated April 10, 2024)
The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the contents of those posts and pages.
0
Attacker Value
Unknown

CVE-2024-1791

Disclosure Date: February 28, 2024 (last updated February 28, 2024)
The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2023-7031

Disclosure Date: January 17, 2024 (last updated January 26, 2024)
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. Affected versions include 8.0.x and 8.1.x, prior to 8.1.2 patch 0402. Versions prior to 8.0 are end of manufacturer support.
Attacker Value
Unknown

CVE-2023-50609

Disclosure Date: January 06, 2024 (last updated January 12, 2024)
Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote attackers to execute arbitrary code via a crafted script to ajax.aspx.
Attacker Value
Unknown

CVE-2023-51084

Disclosure Date: December 27, 2023 (last updated January 05, 2024)
hyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.
Attacker Value
Unknown

CVE-2023-47659

Disclosure Date: November 14, 2023 (last updated November 21, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
Attacker Value
Unknown

CVE-2023-5760

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.
Attacker Value
Unknown

CVE-2023-38473

Disclosure Date: November 02, 2023 (last updated November 10, 2023)
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
Attacker Value
Unknown

CVE-2023-38472

Disclosure Date: November 02, 2023 (last updated November 10, 2023)
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.