Show filters
335,424 Total Results
Displaying 601-610 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2020-26063

Disclosure Date: November 18, 2024 (last updated November 19, 2024)
A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization. The vulnerability is due to improper authorization checks on API endpoints. An attacker could exploit this vulnerability by sending malicious requests to an API endpoint. An exploit could allow the attacker to download files from or modify limited configuration options on the affected system.There are no workarounds that address this vulnerability.
Attacker Value
Unknown

CVE-2020-26062

Disclosure Date: November 18, 2024 (last updated November 19, 2024)
A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in authentication responses sent back from the application as part of an authentication attempt. An attacker could exploit this vulnerability by sending authentication requests to the affected application. A successful exploit could allow the attacker to confirm the names of administrative user accounts for use in further attacks.There are no workarounds that address this vulnerability.
Attacker Value
Unknown

CVE-2024-52436

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Post SMTP allows Blind SQL Injection.This issue affects Post SMTP: from n/a through 2.9.9.
Attacker Value
Unknown

CVE-2024-52435

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in W3 Eden, Inc. Premium Packages allows SQL Injection.This issue affects Premium Packages: from n/a through 5.9.3.
Attacker Value
Unknown

CVE-2024-52434

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic Popup by Supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through 1.10.29.
Attacker Value
Unknown

CVE-2024-52433

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free allows Object Injection.This issue affects My Geo Posts Free: from n/a through 1.2.
Attacker Value
Unknown

CVE-2024-52432

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through 0.0.4.
Attacker Value
Unknown

CVE-2024-52431

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPress Video Robot - The Ultimate Video Importer allows SQL Injection.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0.
Attacker Value
Unknown

CVE-2024-52430

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Deserialization of Untrusted Data vulnerability in Lis Lis Video Gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through 0.2.1.
Attacker Value
Unknown

CVE-2024-52429

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Anton Hoelstad WP Quick Setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through 2.0.