Show filters
8,645 Total Results
Displaying 641-650 of 8,645
Sort by:
Attacker Value
Unknown

CVE-2024-10183

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems.
0
Attacker Value
Unknown

CVE-2024-49273

Disclosure Date: October 21, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid.This issue affects ProfileGrid: from n/a through 5.9.3.
Attacker Value
Unknown

CVE-2024-49306

Disclosure Date: October 20, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in WP-buy WP Content Copy Protection & No Right Click allows Cross Site Request Forgery.This issue affects WP Content Copy Protection & No Right Click: from n/a through 3.5.9.
Attacker Value
Unknown

CVE-2024-49331

Disclosure Date: October 20, 2024 (last updated February 26, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Property Lot Management System allows Upload a Web Shell to a Web Server.This issue affects Property Lot Management System: from n/a through 4.2.38.
Attacker Value
Unknown

CVE-2024-49611

Disclosure Date: October 20, 2024 (last updated February 26, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Paxman Product Website Showcase allows Upload a Web Shell to a Web Server.This issue affects Product Website Showcase: from n/a through 1.0.
Attacker Value
Unknown

CVE-2024-21536

Disclosure Date: October 19, 2024 (last updated February 26, 2025)
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
Attacker Value
Unknown

CVE-2024-47487

Disclosure Date: October 18, 2024 (last updated February 26, 2025)
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.
Attacker Value
Unknown

CVE-2024-9848

Disclosure Date: October 18, 2024 (last updated February 26, 2025)
The Product Customizer Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Attacker Value
Unknown

CVE-2024-9383

Disclosure Date: October 18, 2024 (last updated February 26, 2025)
The Parcel Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-49298

Disclosure Date: October 17, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice allows Stored XSS.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.6.
0