Show filters
536 Total Results
Displaying 61-70 of 536
Sort by:
Attacker Value
Unknown
CVE-2024-49403
Disclosure Date: November 06, 2024 (last updated November 13, 2024)
Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the lock screen.
0
Attacker Value
Unknown
CVE-2024-10733
Disclosure Date: November 03, 2024 (last updated November 06, 2024)
A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-43343
Disclosure Date: November 01, 2024 (last updated November 13, 2024)
Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12.
0
Attacker Value
Unknown
CVE-2024-43254
Disclosure Date: November 01, 2024 (last updated February 11, 2025)
Missing Authorization vulnerability in Zaytech Smart Online Order for Clover allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Online Order for Clover: from n/a through 1.5.6.
0
Attacker Value
Unknown
CVE-2024-43253
Disclosure Date: November 01, 2024 (last updated February 11, 2025)
Missing Authorization vulnerability in Zaytech Smart Online Order for Clover allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Smart Online Order for Clover: from n/a through 1.5.6.
0
Attacker Value
Unknown
CVE-2024-37201
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in javmah Woocommerce Customers Order History allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woocommerce Customers Order History: from n/a through 5.2.2.
0
Attacker Value
Unknown
CVE-2024-10544
Disclosure Date: October 31, 2024 (last updated January 06, 2025)
The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.1.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information about users contained in the exposed log files.
0
Attacker Value
Unknown
CVE-2024-10233
Disclosure Date: October 29, 2024 (last updated October 29, 2024)
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-50497
Disclosure Date: October 28, 2024 (last updated November 01, 2024)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuyNowDepot Advanced Online Ordering and Delivery Platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery Platform: from n/a through 2.0.0.
0
Attacker Value
Unknown
CVE-2024-9686
Disclosure Date: October 25, 2024 (last updated November 07, 2024)
The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nktgnfw_send_test_message' function in versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to send a test message via the Telegram Bot API to the user configured in the settings.
0