Show filters
754 Total Results
Displaying 61-70 of 754
Sort by:
Attacker Value
Unknown
CVE-2023-51776
Disclosure Date: July 02, 2024 (last updated July 06, 2024)
Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-5544
Disclosure Date: July 02, 2024 (last updated July 06, 2024)
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-3017
Disclosure Date: June 27, 2024 (last updated June 28, 2024)
In a
Silicon Labs multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.
0
Attacker Value
Unknown
CVE-2024-5605
Disclosure Date: June 20, 2024 (last updated July 18, 2024)
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2024-38468
Disclosure Date: June 16, 2024 (last updated August 08, 2024)
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
0
Attacker Value
Unknown
CVE-2024-38466
Disclosure Date: June 16, 2024 (last updated August 08, 2024)
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
0
Attacker Value
Unknown
CVE-2024-38465
Disclosure Date: June 16, 2024 (last updated August 08, 2024)
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.
0
Attacker Value
Unknown
CVE-2024-35359
Disclosure Date: May 30, 2024 (last updated July 19, 2024)
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection.
0
Attacker Value
Unknown
CVE-2024-35349
Disclosure Date: May 30, 2024 (last updated July 19, 2024)
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument id can result in SQL injection.
0
Attacker Value
Unknown
CVE-2024-5292
Disclosure Date: May 23, 2024 (last updated May 24, 2024)
D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of D-Link Network Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the DNACore service. The service loads a file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21426.
0