Show filters
8,628 Total Results
Displaying 451-460 of 8,628
Sort by:
Attacker Value
Unknown

CVE-2024-11732

Disclosure Date: December 03, 2024 (last updated February 27, 2025)
The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter in all versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2024-11453

Disclosure Date: December 03, 2024 (last updated February 27, 2025)
The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_pin_widget' shortcode in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-53728

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in SEO-Küche Internet Marketing GmbH & Co. KG Protect Your Content allows Stored XSS.This issue affects Protect Your Content: from n/a through 1.0.2.
0
Attacker Value
Unknown

CVE-2024-52484

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasish Manna Wc Recently viewed products allows Reflected XSS.This issue affects Wc Recently viewed products: from n/a through 1.0.1.
0
Attacker Value
Unknown

CVE-2024-12015

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.
0
Attacker Value
Unknown

CVE-2024-43052

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Memory corruption while processing API calls to NPU with invalid input.
Attacker Value
Unknown

CVE-2024-33056

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Attacker Value
Unknown

CVE-2024-53008

Disclosure Date: November 28, 2024 (last updated February 27, 2025)
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.
0
Attacker Value
Unknown

CVE-2024-11083

Disclosure Date: November 27, 2024 (last updated February 27, 2025)
The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
0
Attacker Value
Unknown

CVE-2024-5921

Disclosure Date: November 27, 2024 (last updated February 27, 2025)
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.
0