Show filters
4,018 Total Results
Displaying 521-530 of 4,018
Sort by:
Attacker Value
Unknown
CVE-2024-36518
Disclosure Date: August 12, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.
0
Attacker Value
Unknown
CVE-2024-36035
Disclosure Date: August 12, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.
0
Attacker Value
Unknown
CVE-2024-36034
Disclosure Date: August 12, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.
0
Attacker Value
Unknown
CVE-2024-7350
Disclosure Date: August 08, 2024 (last updated February 26, 2025)
The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to authentication bypass in versions 1.1.6 to 1.1.7. This is due to the plugin not properly verifying a user's identity prior to logging them in when completing a booking. This makes it possible for unauthenticated attackers to log in as registered users, including administrators, if they have access to that user's email. This is only exploitable when the 'Auto login user after successful booking' setting is enabled.
0
Attacker Value
Unknown
CVE-2024-20479
Disclosure Date: August 07, 2024 (last updated February 26, 2025)
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device.
0
Attacker Value
Unknown
CVE-2024-20443
Disclosure Date: August 07, 2024 (last updated February 26, 2025)
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device.
0
Attacker Value
Unknown
CVE-2024-3238
Disclosure Date: August 02, 2024 (last updated February 26, 2025)
The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() function. This makes it possible for unauthenticated attackers to delete arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Please not the CSRF was patched in 5.0.28, however, adequate directory traversal protection wasn't introduced until 5.0.30.
0
Attacker Value
Unknown
CVE-2024-39660
Disclosure Date: August 01, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow Photo Engine allows Stored XSS.This issue affects Photo Engine: from n/a through 6.3.1.
0
Attacker Value
Unknown
CVE-2024-38791
Disclosure Date: August 01, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7.
0
Attacker Value
Unknown
CVE-2024-38770
Disclosure Date: August 01, 2024 (last updated February 26, 2025)
Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.20.
0