Show filters
759 Total Results
Displaying 51-60 of 759
Sort by:
Attacker Value
Unknown
CVE-2024-10399
Disclosure Date: October 30, 2024 (last updated October 30, 2024)
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames and emails of site users.
0
Attacker Value
Unknown
CVE-2024-49639
Disclosure Date: October 29, 2024 (last updated November 01, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Edward Stoever Monitor.Chat allows Reflected XSS.This issue affects Monitor.Chat: from n/a through 1.1.1.
0
Attacker Value
Unknown
CVE-2024-10092
Disclosure Date: October 26, 2024 (last updated October 26, 2024)
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke existing API keys and generate new ones.
0
Attacker Value
Unknown
CVE-2024-38314
Disclosure Date: October 24, 2024 (last updated October 25, 2024)
IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker that has compromised environment.
0
Attacker Value
Unknown
CVE-2024-49681
Disclosure Date: October 24, 2024 (last updated October 25, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SWIT WP Sessions Time Monitoring Full Automatic allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through 1.0.9.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2022-4972
Disclosure Date: October 16, 2024 (last updated October 31, 2024)
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for administrators.
0
Attacker Value
Unknown
CVE-2024-38097
Disclosure Date: October 08, 2024 (last updated October 17, 2024)
Azure Monitor Agent Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-9005
Disclosure Date: October 08, 2024 (last updated October 08, 2024)
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be
remotely executed on the server when unsafely deserialized data is posted to the web server.
0
Attacker Value
Unknown
CVE-2024-8884
Disclosure Date: October 08, 2024 (last updated October 08, 2024)
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that
could cause exposure of credentials when attacker has access to application on network over
http
0