Show filters
1,324 Total Results
Displaying 71-80 of 1,324
Sort by:
Attacker Value
Unknown
CVE-2024-51661
Disclosure Date: November 04, 2024 (last updated November 09, 2024)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media Library Assistant allows Command Injection.This issue affects Media Library Assistant: from n/a through 3.19.
0
Attacker Value
Unknown
CVE-2024-50511
Disclosure Date: October 30, 2024 (last updated October 30, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in David DONISA WP donimedia carousel allows Upload a Web Shell to a Web Server.This issue affects WP donimedia carousel: from n/a through 1.0.1.
0
Attacker Value
Unknown
CVE-2024-10412
Disclosure Date: October 27, 2024 (last updated October 30, 2024)
A vulnerability was found in Poco-z Guns-Medical 1.0. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /mgr/upload of the component File Upload. The manipulation of the argument picture leads to cross site scripting. The attack can be launched remotely.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-9802
Disclosure Date: October 10, 2024 (last updated December 20, 2024)
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.
0
Attacker Value
Unknown
CVE-2024-9798
Disclosure Date: October 10, 2024 (last updated December 20, 2024)
The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
0
Attacker Value
Unknown
CVE-2024-47841
Disclosure Date: October 05, 2024 (last updated October 17, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Path Traversal.This issue affects Mediawiki - CSS Extension: from 1.42.X before 1.42.2, from 1.41.X before 1.41.3, from 1.39.X before 1.39.9.
0
Attacker Value
Unknown
CVE-2024-47845
Disclosure Date: October 05, 2024 (last updated October 24, 2024)
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects Mediawiki - CSS Extension: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.
0
Attacker Value
Unknown
CVE-2024-47848
Disclosure Date: October 05, 2024 (last updated October 05, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTriage allows Authentication Bypass.This issue affects Mediawiki - PageTriage: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.
0
Attacker Value
Unknown
CVE-2024-9220
Disclosure Date: October 01, 2024 (last updated October 08, 2024)
The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.08. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0