Show filters
4,015 Total Results
Displaying 531-540 of 4,015
Sort by:
Attacker Value
Unknown

CVE-2024-41141

Disclosure Date: July 30, 2024 (last updated February 26, 2025)
Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Management feature and one of them inputs some crafted value on the OAuth Management page, an arbitrary script may be executed on the web browser of the other user who accessed the management page.
0
Attacker Value
Unknown

CVE-2024-6726

Disclosure Date: July 29, 2024 (last updated February 26, 2025)
Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE).
0
Attacker Value
Unknown

CVE-2024-6591

Disclosure Date: July 27, 2024 (last updated February 26, 2025)
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' and 'resend_auction_email_callback' functions in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to craft emails that include links and send to any email address.
0
Attacker Value
Unknown

CVE-2024-38872

Disclosure Date: July 26, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.
Attacker Value
Unknown

CVE-2024-38871

Disclosure Date: July 26, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.
Attacker Value
Unknown

CVE-2024-7069

Disclosure Date: July 24, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects some unknown processing of the file /employee_gatepass/classes/Master.php?f=delete_department. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272351.
Attacker Value
Unknown

CVE-2024-36541

Disclosure Date: July 24, 2024 (last updated February 26, 2025)
Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
Attacker Value
Unknown

CVE-2024-0981

Disclosure Date: July 23, 2024 (last updated February 26, 2025)
Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these credentials within Okta Personal. A fix was implemented to properly escape these fields, addressing the vulnerability. Importantly, if Okta Personal is not added to the plugin to enable multi-account view, the Workforce Identity Cloud plugin is not affected by this issue. The vulnerability is fixed in Okta Browser Plugin version 6.32.0 for Chrome/Edge/Safari/Firefox.
0
Attacker Value
Unknown

CVE-2024-37429

Disclosure Date: July 22, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hamid Alinia – idehweb Login with phone number allows Stored XSS.This issue affects Login with phone number: from n/a through 1.7.35.
Attacker Value
Unknown

CVE-2024-6967

Disclosure Date: July 22, 2024 (last updated February 26, 2025)
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as critical. This affects an unknown part of the file /employee_gatepass/admin/?page=employee/manage_employee. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272121 was assigned to this vulnerability.