Show filters
590 Total Results
Displaying 71-80 of 590
Sort by:
Attacker Value
Unknown
CVE-2024-38408
Disclosure Date: November 04, 2024 (last updated November 09, 2024)
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
0
Attacker Value
Unknown
CVE-2024-9627
Disclosure Date: October 22, 2024 (last updated October 26, 2024)
The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'service_process' function in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to view the Telegram Bot Token, which is a secret token to control the bot.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-9821
Disclosure Date: October 12, 2024 (last updated January 06, 2025)
The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to view the Telegram Bot Token, a secret token used to control the bot, which can then be used to log in as any existing user on the site, such as an administrator, if they know the username, due to the Login with Telegram feature.
0
Attacker Value
Unknown
CVE-2024-6157
Disclosure Date: October 10, 2024 (last updated October 12, 2024)
An attacker who successfully exploited these vulnerabilities could cause the robot to stop.
A vulnerability exists in the PROFINET stack included in the RobotWare versions listed below.
This vulnerability arises under specific condition when specially crafted message is processed by the system.
Below are reported vulnerabilities in the Robot Ware versions.
* IRC5- RobotWare 6 < 6.15.06 except 6.10.10, and 6.13.07
0
Attacker Value
Unknown
CVE-2024-8264
Disclosure Date: October 09, 2024 (last updated October 18, 2024)
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.
0
Attacker Value
Unknown
CVE-2024-38397
Disclosure Date: October 07, 2024 (last updated October 17, 2024)
Transient DOS while parsing probe response and assoc response frame.
0
Attacker Value
Unknown
CVE-2024-33073
Disclosure Date: October 07, 2024 (last updated October 17, 2024)
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
0
Attacker Value
Unknown
CVE-2024-8776
Disclosure Date: September 16, 2024 (last updated September 21, 2024)
SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting attacks.
0
Attacker Value
Unknown
CVE-2024-6846
Disclosure Date: September 05, 2024 (last updated September 05, 2024)
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
0