Show filters
234 Total Results
Displaying 51-60 of 234
Sort by:
Attacker Value
Unknown

CVE-2024-43947

Disclosure Date: August 29, 2024 (last updated September 05, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.
Attacker Value
Unknown

CVE-2024-43948

Disclosure Date: August 29, 2024 (last updated September 04, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.
Attacker Value
Unknown

CVE-2024-22217

Disclosure Date: August 15, 2024 (last updated September 12, 2024)
A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on.
Attacker Value
Unknown

CVE-2024-33978

Disclosure Date: August 06, 2024 (last updated August 16, 2024)
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.
Attacker Value
Unknown

CVE-2024-33977

Disclosure Date: August 06, 2024 (last updated August 16, 2024)
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in /admin/orders/index.php'.
Attacker Value
Unknown

CVE-2024-33976

Disclosure Date: August 06, 2024 (last updated August 16, 2024)
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'id' parameter in '/admin/user/index.php'.
Attacker Value
Unknown

CVE-2024-33975

Disclosure Date: August 06, 2024 (last updated August 16, 2024)
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'view' parameter in '/admin/products/index.php'.
Attacker Value
Unknown

CVE-2024-33958

Disclosure Date: August 06, 2024 (last updated August 16, 2024)
SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'phonenumber' in '/passwordrecover.php' parameter.
Attacker Value
Unknown

CVE-2024-33957

Disclosure Date: August 06, 2024 (last updated August 16, 2024)
SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'id' in '/admin/orders/controller.php' parameter
Attacker Value
Unknown

CVE-2024-37952

Disclosure Date: July 09, 2024 (last updated August 17, 2024)
Improper Privilege Management vulnerability in themeenergy BookYourTravel allows Privilege Escalation.This issue affects BookYourTravel: from n/a through 8.18.17.