Show filters
370 Total Results
Displaying 51-60 of 370
Sort by:
Attacker Value
Unknown
CVE-2024-37271
Disclosure Date: July 22, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Nelson Print My Blog allows Stored XSS.This issue affects Print My Blog: from n/a through 3.27.0.
0
Attacker Value
Unknown
CVE-2024-24051
Disclosure Date: June 12, 2024 (last updated November 21, 2024)
Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file.
0
Attacker Value
Unknown
CVE-2024-32777
Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint.This issue affects BizPrint: from n/a through 4.3.39.
0
Attacker Value
Unknown
CVE-2024-5143
Disclosure Date: May 23, 2024 (last updated May 24, 2024)
A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By redirecting send-to-email traffic to the new server, the original SMTP server credentials may potentially be exposed.
0
Attacker Value
Unknown
CVE-2024-3671
Disclosure Date: May 22, 2024 (last updated January 05, 2025)
The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'print-me' shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes such as 'tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-3286
Disclosure Date: May 16, 2024 (last updated January 05, 2025)
A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.
0
Attacker Value
Unknown
CVE-2024-32977
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within `config.yaml`, even if they come from networks that are not configured as `localNetworks`, spoofing their IP via the `X-Forwarded-For` header. If autologin is not enabled, this vulnerability does not have any impact. The vulnerability has been patched in version 1.10.1. Until the patch has been applied, OctoPrint administrators who have autologin enabled on their instances should disable it and/or to make the instance inaccessible from potentially hostile networks like the internet.
0
Attacker Value
Unknown
CVE-2023-5447
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics Hardware Support App.
0
Attacker Value
Unknown
CVE-2024-4233
Disclosure Date: May 08, 2024 (last updated May 09, 2024)
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ: from n/a through 1.9.3.
0
Attacker Value
Unknown
CVE-2024-33907
Disclosure Date: May 06, 2024 (last updated May 07, 2024)
Missing Authorization vulnerability in Michael Nelson Print My Blog.This issue affects Print My Blog: from n/a through 3.26.2.
0