Show filters
1,430 Total Results
Displaying 71-80 of 1,430
Sort by:
Attacker Value
Unknown

CVE-2024-47241

Disclosure Date: October 18, 2024 (last updated December 18, 2024)
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access and modification of transmitted data.
Attacker Value
Unknown

CVE-2024-47240

Disclosure Date: October 18, 2024 (last updated October 23, 2024)
Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the file system and could potentially exploit this vulnerability to gain write access to unauthorized data and cause a version update failure condition.
Attacker Value
Unknown

CVE-2024-49399

Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information.
0
Attacker Value
Unknown

CVE-2024-49398

Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.
0
Attacker Value
Unknown

CVE-2024-49397

Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication and takeover admin accounts.
0
Attacker Value
Unknown

CVE-2024-49396

Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.
0
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-47395

Disclosure Date: October 05, 2024 (last updated October 06, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Robokassa Robokassa payment gateway for Woocommerce allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through 1.6.1.
0
Attacker Value
Unknown

CVE-2024-47646

Disclosure Date: October 05, 2024 (last updated October 06, 2024)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payflex Payflex Payment Gateway.This issue affects Payflex Payment Gateway: from n/a through 2.6.1.
0
Attacker Value
Unknown

CVE-2024-9276

Disclosure Date: September 27, 2024 (last updated September 27, 2024)
A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of the argument console/nocache/cmd leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0