Show filters
917 Total Results
Displaying 71-80 of 917
Sort by:
Attacker Value
Unknown

CVE-2024-8729

Disclosure Date: October 10, 2024 (last updated October 16, 2024)
The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-43503

Disclosure Date: October 08, 2024 (last updated October 18, 2024)
Microsoft SharePoint Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-47326

Disclosure Date: October 06, 2024 (last updated October 06, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ILLID Share This Image allows Reflected XSS.This issue affects Share This Image: from n/a through 2.01.
0
Attacker Value
Unknown

CVE-2024-9174

Disclosure Date: October 02, 2024 (last updated October 02, 2024)
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
0
Attacker Value
Unknown

CVE-2024-7400

Disclosure Date: September 27, 2024 (last updated September 27, 2024)
The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.
0
Attacker Value
Unknown

CVE-2024-47330

Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons by Supsystic: from n/a through 2.2.9.
Attacker Value
Unknown

CVE-2024-8761

Disclosure Date: September 17, 2024 (last updated September 28, 2024)
The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Attacker Value
Unknown

CVE-2024-38315

Disclosure Date: September 16, 2024 (last updated September 21, 2024)
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
Attacker Value
Unknown

CVE-2024-43466

Disclosure Date: September 10, 2024 (last updated September 14, 2024)
Microsoft SharePoint Server Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2024-43464

Disclosure Date: September 10, 2024 (last updated September 14, 2024)
Microsoft SharePoint Server Remote Code Execution Vulnerability