Show filters
1,430 Total Results
Displaying 71-80 of 1,430
Sort by:
Attacker Value
Unknown
CVE-2024-47241
Disclosure Date: October 18, 2024 (last updated December 18, 2024)
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access and modification of transmitted data.
0
Attacker Value
Unknown
CVE-2024-47240
Disclosure Date: October 18, 2024 (last updated October 23, 2024)
Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the file system and could potentially exploit this vulnerability to gain write access to unauthorized data and cause a version update failure condition.
0
Attacker Value
Unknown
CVE-2024-49399
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information.
0
Attacker Value
Unknown
CVE-2024-49398
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.
0
Attacker Value
Unknown
CVE-2024-49397
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication and takeover admin accounts.
0
Attacker Value
Unknown
CVE-2024-49396
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-47395
Disclosure Date: October 05, 2024 (last updated October 06, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Robokassa Robokassa payment gateway for Woocommerce allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through 1.6.1.
0
Attacker Value
Unknown
CVE-2024-47646
Disclosure Date: October 05, 2024 (last updated October 06, 2024)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payflex Payflex Payment Gateway.This issue affects Payflex Payment Gateway: from n/a through 2.6.1.
0
Attacker Value
Unknown
CVE-2024-9276
Disclosure Date: September 27, 2024 (last updated September 27, 2024)
A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of the argument console/nocache/cmd leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0