Show filters
440 Total Results
Displaying 51-60 of 440
Sort by:
Attacker Value
Unknown

CVE-2024-6624

Disclosure Date: July 11, 2024 (last updated July 13, 2024)
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.
Attacker Value
Unknown

CVE-2024-3826

Disclosure Date: July 02, 2024 (last updated July 30, 2024)
In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.
0
Attacker Value
Unknown

CVE-2024-3468

Disclosure Date: June 12, 2024 (last updated June 13, 2024)
There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.
0
Attacker Value
Unknown

CVE-2024-34377

Disclosure Date: May 06, 2024 (last updated May 07, 2024)
Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3.
0
Attacker Value
Unknown

CVE-2024-2796

Disclosure Date: April 18, 2024 (last updated September 09, 2024)
A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.
0
Attacker Value
Unknown

CVE-2024-31848

Disclosure Date: April 05, 2024 (last updated January 05, 2025)
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
0
Attacker Value
Unknown

CVE-2024-30242

Disclosure Date: March 28, 2024 (last updated January 05, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions Contact Form to Any API.This issue affects Contact Form to Any API: from n/a through 1.1.8.
0
Attacker Value
Unknown

CVE-2023-50093

Disclosure Date: January 03, 2024 (last updated January 10, 2024)
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
Attacker Value
Unknown

CVE-2023-50092

Disclosure Date: January 03, 2024 (last updated January 10, 2024)
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2024-0196

Disclosure Date: January 02, 2024 (last updated January 10, 2024)
A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /resource/file/api/save?auto=1. The manipulation leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249511.