Show filters
440 Total Results
Displaying 51-60 of 440
Sort by:
Attacker Value
Unknown
CVE-2024-6624
Disclosure Date: July 11, 2024 (last updated July 13, 2024)
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.
0
Attacker Value
Unknown
CVE-2024-3826
Disclosure Date: July 02, 2024 (last updated July 30, 2024)
In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.
0
Attacker Value
Unknown
CVE-2024-3468
Disclosure Date: June 12, 2024 (last updated June 13, 2024)
There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.
0
Attacker Value
Unknown
CVE-2024-34377
Disclosure Date: May 06, 2024 (last updated May 07, 2024)
Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3.
0
Attacker Value
Unknown
CVE-2024-2796
Disclosure Date: April 18, 2024 (last updated September 09, 2024)
A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.
0
Attacker Value
Unknown
CVE-2024-31848
Disclosure Date: April 05, 2024 (last updated January 05, 2025)
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
0
Attacker Value
Unknown
CVE-2024-30242
Disclosure Date: March 28, 2024 (last updated January 05, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions Contact Form to Any API.This issue affects Contact Form to Any API: from n/a through 1.1.8.
0
Attacker Value
Unknown
CVE-2023-50093
Disclosure Date: January 03, 2024 (last updated January 10, 2024)
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
0
Attacker Value
Unknown
CVE-2023-50092
Disclosure Date: January 03, 2024 (last updated January 10, 2024)
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).
0
Attacker Value
Unknown
CVE-2024-0196
Disclosure Date: January 02, 2024 (last updated January 10, 2024)
A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /resource/file/api/save?auto=1. The manipulation leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249511.
0