Show filters
234 Total Results
Displaying 51-60 of 234
Sort by:
Attacker Value
Unknown
CVE-2024-43947
Disclosure Date: August 29, 2024 (last updated September 05, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.
0
Attacker Value
Unknown
CVE-2024-43948
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.
0
Attacker Value
Unknown
CVE-2024-22217
Disclosure Date: August 15, 2024 (last updated September 12, 2024)
A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on.
0
Attacker Value
Unknown
CVE-2024-33978
Disclosure Date: August 06, 2024 (last updated August 16, 2024)
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.
0
Attacker Value
Unknown
CVE-2024-33977
Disclosure Date: August 06, 2024 (last updated August 16, 2024)
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in /admin/orders/index.php'.
0
Attacker Value
Unknown
CVE-2024-33976
Disclosure Date: August 06, 2024 (last updated August 16, 2024)
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'id' parameter in '/admin/user/index.php'.
0
Attacker Value
Unknown
CVE-2024-33975
Disclosure Date: August 06, 2024 (last updated August 16, 2024)
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'view' parameter in '/admin/products/index.php'.
0
Attacker Value
Unknown
CVE-2024-33958
Disclosure Date: August 06, 2024 (last updated August 16, 2024)
SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'phonenumber' in '/passwordrecover.php' parameter.
0
Attacker Value
Unknown
CVE-2024-33957
Disclosure Date: August 06, 2024 (last updated August 16, 2024)
SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'id' in '/admin/orders/controller.php' parameter
0
Attacker Value
Unknown
CVE-2024-37952
Disclosure Date: July 09, 2024 (last updated August 17, 2024)
Improper Privilege Management vulnerability in themeenergy BookYourTravel allows Privilege Escalation.This issue affects BookYourTravel: from n/a through 8.18.17.
0