Show filters
1,013 Total Results
Displaying 41-50 of 1,013
Sort by:
Attacker Value
Unknown

CVE-2024-9505

Disclosure Date: October 29, 2024 (last updated November 01, 2024)
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-45276

Disclosure Date: October 15, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
0
Attacker Value
Unknown

CVE-2024-45275

Disclosure Date: October 15, 2024 (last updated October 18, 2024)
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
Attacker Value
Unknown

CVE-2024-45274

Disclosure Date: October 15, 2024 (last updated October 18, 2024)
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
Attacker Value
Unknown

CVE-2024-45273

Disclosure Date: October 15, 2024 (last updated October 18, 2024)
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Attacker Value
Unknown

CVE-2024-45272

Disclosure Date: October 15, 2024 (last updated October 18, 2024)
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
Attacker Value
Unknown

CVE-2024-45271

Disclosure Date: October 15, 2024 (last updated October 22, 2024)
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
Attacker Value
Unknown

CVE-2024-47389

Disclosure Date: October 05, 2024 (last updated January 23, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows Reflected XSS.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.3.
Attacker Value
Unknown

CVE-2024-9441

Disclosure Date: October 02, 2024 (last updated October 03, 2024)
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.
0