Show filters
977 Total Results
Displaying 71-80 of 977
Sort by:
Attacker Value
Unknown
CVE-2024-9162
Disclosure Date: October 28, 2024 (last updated January 06, 2025)
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export file with the .php extension on the affected site's server, adding an arbitrary PHP code to it, which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2024-49684
Disclosure Date: October 23, 2024 (last updated October 24, 2024)
Deserialization of Untrusted Data vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.21.
0
Attacker Value
Unknown
CVE-2024-48024
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
: Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Daily allows Retrieve Embedded Sensitive Data.This issue affects Keep Backup Daily: from n/a through 2.0.7.
0
Attacker Value
Unknown
CVE-2020-36842
Disclosure Date: October 16, 2024 (last updated October 31, 2024)
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affects versions up to, and including 0.9.35.
0
Attacker Value
Unknown
CVE-2020-36835
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.
0
Attacker Value
Unknown
CVE-2024-48020
Disclosure Date: October 11, 2024 (last updated October 12, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Revmakx Backup and Staging by WP Time Capsule allows SQL Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.21.
0
Attacker Value
Unknown
CVE-2024-7315
Disclosure Date: October 02, 2024 (last updated October 02, 2024)
The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.
0
Attacker Value
Unknown
CVE-2023-52950
Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors.
0
Attacker Value
Unknown
CVE-2023-52949
Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
0
Attacker Value
Unknown
CVE-2023-52948
Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
0