Show filters
892 Total Results
Displaying 71-80 of 892
Sort by:
Attacker Value
Unknown

CVE-2024-5703

Disclosure Date: July 17, 2024 (last updated July 20, 2024)
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with Subscriber-level access and above, to access the API (provided it is enabled) and add, edit, and delete audience users.
Attacker Value
Unknown

CVE-2024-37115

Disclosure Date: July 10, 2024 (last updated July 11, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown

CVE-2024-37424

Disclosure Date: July 09, 2024 (last updated July 09, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to a Web Server.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown

CVE-2024-37474

Disclosure Date: July 04, 2024 (last updated August 01, 2024)
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.
Attacker Value
Unknown

CVE-2024-37476

Disclosure Date: July 04, 2024 (last updated November 02, 2024)
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2.31.1.
Attacker Value
Unknown

CVE-2024-6172

Disclosure Date: July 02, 2024 (last updated July 04, 2024)
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2024-37252

Disclosure Date: June 26, 2024 (last updated June 26, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.
0
Attacker Value
Unknown

CVE-2024-37098

Disclosure Date: June 26, 2024 (last updated June 26, 2024)
Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6.
0
Attacker Value
Unknown

CVE-2024-6295

Disclosure Date: June 25, 2024 (last updated January 05, 2025)
udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
0
Attacker Value
Unknown

CVE-2024-6294

Disclosure Date: June 25, 2024 (last updated January 05, 2025)
udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
0