Show filters
561 Total Results
Displaying 51-60 of 561
Sort by:
Attacker Value
Unknown

CVE-2024-45066

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.
Attacker Value
Unknown

CVE-2024-43693

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.
Attacker Value
Unknown

CVE-2024-43692

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.
Attacker Value
Unknown

CVE-2024-43423

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
Attacker Value
Unknown

CVE-2024-41725

Disclosure Date: September 25, 2024 (last updated February 26, 2025)
ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may allow cross site scripting.
Attacker Value
Unknown

CVE-2022-4533

Disclosure Date: September 19, 2024 (last updated February 26, 2025)
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.
Attacker Value
Unknown

CVE-2024-6878

Disclosure Date: September 18, 2024 (last updated February 26, 2025)
Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common Resource Locations.This issue affects Panel: before v2.3.24.
0
Attacker Value
Unknown

CVE-2024-6877

Disclosure Date: September 18, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.
Attacker Value
Unknown

CVE-2024-5960

Disclosure Date: September 18, 2024 (last updated February 26, 2025)
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.
Attacker Value
Unknown

CVE-2024-5959

Disclosure Date: September 18, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS.This issue affects Panel: before v2.3.24.