Show filters
8,629 Total Results
Displaying 481-490 of 8,629
Sort by:
Attacker Value
Unknown
CVE-2024-50054
Disclosure Date: November 22, 2024 (last updated February 27, 2025)
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
0
Attacker Value
Unknown
CVE-2024-47407
Disclosure Date: November 22, 2024 (last updated February 27, 2025)
A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
0
Attacker Value
Unknown
CVE-2024-47138
Disclosure Date: November 22, 2024 (last updated February 27, 2025)
The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.
0
Attacker Value
Unknown
CVE-2024-45369
Disclosure Date: November 22, 2024 (last updated February 27, 2025)
The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.
0
Attacker Value
Unknown
CVE-2024-11225
Disclosure Date: November 22, 2024 (last updated February 27, 2025)
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.9.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-49588
Disclosure Date: November 21, 2024 (last updated February 27, 2025)
Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.
0
Attacker Value
Unknown
CVE-2024-7130
Disclosure Date: November 21, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Computer KION Exchange Programs Software allows Reflected XSS.This issue affects KION Exchange Programs Software: before 1.21.9092.29966.
0
Attacker Value
Unknown
CVE-2024-9442
Disclosure Date: November 21, 2024 (last updated February 27, 2025)
The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
0
Attacker Value
Unknown
CVE-2024-9111
Disclosure Date: November 21, 2024 (last updated February 27, 2025)
The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
0
Attacker Value
Unknown
CVE-2024-11385
Disclosure Date: November 21, 2024 (last updated February 27, 2025)
The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'circle_progress' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0