Show filters
842 Total Results
Displaying 51-60 of 842
Sort by:
Attacker Value
Unknown

CVE-2024-21576

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and FindContour custom nodes. In the entrypoint function to each node, there’s a call to eval which can be triggered by generating a workflow that injects a crafted string into the node. This can result in executing arbitrary code on the server.
0
Attacker Value
Unknown

CVE-2024-12004

Disclosure Date: December 11, 2024 (last updated December 21, 2024)
The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the ajax_update_order_note() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-11945

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-43222

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in SeventhQueen Sweet Date.This issue affects Sweet Date: from n/a through 3.7.3.
0
Attacker Value
Unknown

CVE-2023-51360

Disclosure Date: December 09, 2024 (last updated January 23, 2025)
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.
Attacker Value
Unknown

CVE-2023-51359

Disclosure Date: December 09, 2024 (last updated January 23, 2025)
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.
Attacker Value
Unknown

CVE-2023-49192

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.6.3.
0
Attacker Value
Unknown

CVE-2023-47762

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in WPDeveloper BetterDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterDocs: from n/a through 2.5.2.
0
Attacker Value
Unknown

CVE-2023-47761

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in WPDeveloper Simple 301 Redirects by BetterLinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple 301 Redirects by BetterLinks: from n/a through 2.0.7.
0
Attacker Value
Unknown

CVE-2023-47760

Disclosure Date: December 09, 2024 (last updated January 23, 2025)
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.