Show filters
5,503 Total Results
Displaying 61-70 of 5,503
Sort by:
Attacker Value
Unknown

CVE-2024-40749

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Improper Access Controls allows access to protected views.
0
Attacker Value
Unknown

CVE-2024-40748

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Lack of output escaping in the id attribute of menu lists.
0
Attacker Value
Unknown

CVE-2024-40747

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Various module chromes didn't properly process inputs, leading to XSS vectors.
0
Attacker Value
Unknown

CVE-2024-12907

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parameter sent to /CMSMessages/AccessDenied.aspx endpoint. Notably, support for this version of Kentico ended in 2016. Version 8 was tested as well and does not contain this vulnerability.
0
Attacker Value
Unknown

CVE-2024-47920

Disclosure Date: December 30, 2024 (last updated January 02, 2025)
Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown

CVE-2024-47919

Disclosure Date: December 30, 2024 (last updated January 02, 2025)
Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
0
Attacker Value
Unknown

CVE-2024-47918

Disclosure Date: December 30, 2024 (last updated January 02, 2025)
Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
0
Attacker Value
Unknown

CVE-2024-13022

Disclosure Date: December 29, 2024 (last updated January 02, 2025)
A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function UploadResponse of the file src/main/java/com/tarzan/cms/modules/admin/controller/common/UploadController.java of the component Article Management. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown

CVE-2024-12901

Disclosure Date: December 23, 2024 (last updated January 05, 2025)
A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the component API Endpoint. The manipulation of the argument password leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown

CVE-2024-12900

Disclosure Date: December 23, 2024 (last updated January 05, 2025)
A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component Configuration File Handler. The manipulation of the argument database password leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0