Show filters
3,312 Total Results
Displaying 71-80 of 3,312
Sort by:
Attacker Value
Unknown

CVE-2024-13742

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.5 via deserialization of untrusted input from the reqpars parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Attacker Value
Unknown

CVE-2025-0784

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.21.59 is able to address this issue. It is recommended to upgrade the affected component.
Attacker Value
Unknown

CVE-2024-35114

Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.
Attacker Value
Unknown

CVE-2024-35113

Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through a directory listing.
Attacker Value
Unknown

CVE-2024-35112

Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2024-35111

Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2025-22711

Disclosure Date: January 21, 2025 (last updated January 22, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Maier Image Source Control allows Reflected XSS. This issue affects Image Source Control: from n/a through 2.29.0.
0
Attacker Value
Unknown

CVE-2024-13515

Disclosure Date: January 18, 2025 (last updated January 18, 2025)
The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'path' parameter in all versions up to, and including, 2.28.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2018-25108

Disclosure Date: January 16, 2025 (last updated January 16, 2025)
An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.
Attacker Value
Unknown

CVE-2025-22784

Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Johan Ström Background Control allows Path Traversal.This issue affects Background Control: from n/a through 1.0.5.
0