Show filters
200 Total Results
Displaying 51-60 of 200
Sort by:
Attacker Value
Unknown

CVE-2023-26514

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions.
Attacker Value
Unknown

CVE-2021-4353

Disclosure Date: October 20, 2023 (last updated October 27, 2023)
The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including, 2.4.1. This is due to missing authorization on the export() function which makes makes it possible for unauthenticated attackers to export the plugin's settings.
Attacker Value
Unknown

CVE-2023-40559

Disclosure Date: October 04, 2023 (last updated October 09, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin <= 2.4.0 versions.
Attacker Value
Unknown

CVE-2023-34022

Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rakib Hasan Dynamic QR Code Generator plugin <= 0.0.5 versions.
Attacker Value
Unknown

CVE-2022-29470

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Improper access control in the Intel® DTT Software before version 8.7.10400.15482 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2021-4372

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1. This is due to missing sanitization on the settings imported via the import() function. This makes it possible for unauthenticated attackers to import a settings file containing malicious JavaScript that would execute when an administrator accesses the settings area of the site.
Attacker Value
Unknown

CVE-2015-10100

Disclosure Date: April 10, 2023 (last updated December 21, 2024)
A vulnerability, which was classified as critical, has been found in Dynamic Widgets Plugin up to 1.5.10 on WordPress. This issue affects some unknown processing of the file classes/dynwid_class.php. The manipulation leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.5.11 is able to address this issue. The identifier of the patch is d0a19c6efcdc86d7093b369bc9e29a0629e57795. It is recommended to upgrade the affected component. The identifier VDB-225353 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-26857

Disclosure Date: April 05, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in /admin/ajax.php?action=save_uploads of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2023-26856

Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/ajax.php?action=login.
Attacker Value
Unknown

CVE-2023-0326

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence.