Show filters
1,135 Total Results
Displaying 71-80 of 1,135
Sort by:
Attacker Value
Unknown
CVE-2021-39081
Disclosure Date: December 19, 2024 (last updated December 19, 2024)
IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
0
Attacker Value
Unknown
CVE-2024-11254
Disclosure Date: December 18, 2024 (last updated December 18, 2024)
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-54295
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Authentication Bypass Using an Alternate Path or Channel vulnerability in InspireUI ListApp Mobile Manager allows Authentication Bypass.This issue affects ListApp Mobile Manager: from n/a through 1.7.7.
0
Attacker Value
Unknown
CVE-2024-12420
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 11.52. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
0
Attacker Value
Unknown
CVE-2024-5020
Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-54000
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when a request to .well-known/assetlinks.json" returns a 302 redirect. This is a bypass of the fix for CVE-2024-29190 and is fixed in 3.9.7.
0
Attacker Value
Unknown
CVE-2024-53999
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users in the application use the "Diff or Compare" functionality, they are affected by a Stored Cross-Site Scripting vulnerability. This vulnerability is fixed in 4.2.9.
0
Attacker Value
Unknown
CVE-2024-49412
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.
0
Attacker Value
Unknown
CVE-2024-43053
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.
0
Attacker Value
Unknown
CVE-2024-43052
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption while processing API calls to NPU with invalid input.
0