Show filters
9,976 Total Results
Displaying 631-640 of 9,976
Sort by:
Attacker Value
Unknown

CVE-2024-48035

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Takayuki Imanishi ACF Images Search And Insert allows Upload a Web Shell to a Web Server.This issue affects ACF Images Search And Insert: from n/a through 1.1.4.
0
Attacker Value
Unknown

CVE-2024-47351

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider allows Path Traversal.This issue affects MaxSlider: from n/a through 1.2.3.
0
Attacker Value
Unknown

CVE-2024-49257

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting allows Upload a Web Shell to a Web Server.This issue affects Azz Anonim Posting: from n/a through 0.9.
0
Attacker Value
Unknown

CVE-2023-7295

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2021-4451

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (WordPress, and NinjaFirewall).
Attacker Value
Unknown

CVE-2024-49388

Disclosure Date: October 15, 2024 (last updated February 26, 2025)
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Attacker Value
Unknown

CVE-2024-49387

Disclosure Date: October 15, 2024 (last updated February 26, 2025)
Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Attacker Value
Unknown

CVE-2024-49384

Disclosure Date: October 15, 2024 (last updated February 26, 2025)
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Attacker Value
Unknown

CVE-2024-49383

Disclosure Date: October 15, 2024 (last updated February 26, 2025)
Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.