Show filters
10,549 Total Results
Displaying 401-410 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2024-47137
Disclosure Date: November 05, 2024 (last updated February 27, 2025)
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.
0
Attacker Value
Unknown
CVE-2024-51734
Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to upgrade. Users unable to upgrade may address the issue by adding `data__roles__ = ()` to `AccessControl.userfolder.UserFolder`.
0
Attacker Value
Unknown
CVE-2024-51136
Disclosure Date: November 04, 2024 (last updated February 27, 2025)
An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.
0
Attacker Value
Unknown
CVE-2024-51672
Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1.7.
0
Attacker Value
Unknown
CVE-2024-50525
Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Helloprint Plug your WooCommerce into the largest catalog of customized print products from Helloprint allows Upload a Web Shell to a Web Server.This issue affects Plug your WooCommerce into the largest catalog of customized print products from Helloprint: from n/a through 2.0.2.
0
Attacker Value
Unknown
CVE-2024-43323
Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.
0
Attacker Value
Unknown
CVE-2024-43212
Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.7.7.
0
Attacker Value
Unknown
CVE-2024-43211
Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps MailChimp Subscribe Forms allows Stored XSS.This issue affects MailChimp Subscribe Forms : from n/a through 4.0.9.9.
0
Attacker Value
Unknown
CVE-2024-38707
Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a through 4.0.4.
0
Attacker Value
Unknown
CVE-2024-37456
Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Noptin Newsletter Noptin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Noptin: from n/a through 3.4.2.
0