Show filters
754 Total Results
Displaying 61-70 of 754
Sort by:
Attacker Value
Unknown

CVE-2023-51776

Disclosure Date: July 02, 2024 (last updated July 06, 2024)
Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.
Attacker Value
Unknown

CVE-2024-5544

Disclosure Date: July 02, 2024 (last updated July 06, 2024)
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-3017

Disclosure Date: June 27, 2024 (last updated June 28, 2024)
In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.
0
Attacker Value
Unknown

CVE-2024-5605

Disclosure Date: June 20, 2024 (last updated July 18, 2024)
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2024-38468

Disclosure Date: June 16, 2024 (last updated August 08, 2024)
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
Attacker Value
Unknown

CVE-2024-38466

Disclosure Date: June 16, 2024 (last updated August 08, 2024)
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
Attacker Value
Unknown

CVE-2024-38465

Disclosure Date: June 16, 2024 (last updated August 08, 2024)
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.
Attacker Value
Unknown

CVE-2024-35359

Disclosure Date: May 30, 2024 (last updated July 19, 2024)
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection.
Attacker Value
Unknown

CVE-2024-35349

Disclosure Date: May 30, 2024 (last updated July 19, 2024)
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument id can result in SQL injection.
Attacker Value
Unknown

CVE-2024-5292

Disclosure Date: May 23, 2024 (last updated May 24, 2024)
D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of D-Link Network Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the DNACore service. The service loads a file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21426.
0