Show filters
2,513 Total Results
Displaying 71-80 of 2,513
Sort by:
Attacker Value
Unknown

CVE-2025-20033

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_notification type and specific props.
0
Attacker Value
Unknown

CVE-2025-22130

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them permissions. This is patched in v0.8.2.
0
Attacker Value
Unknown

CVE-2024-12713

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password protected, private, or draft posts that they should not have access to.
Attacker Value
Unknown

CVE-2025-22577

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Damion Armentrout Able Player allows DOM-Based XSS.This issue affects Able Player: from n/a through 1.0.
0
Attacker Value
Unknown

CVE-2025-22524

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in instaform.ir فرم ساز فرم افزار allows Stored XSS.This issue affects فرم ساز فرم افزار: from n/a through 2.0.
0
Attacker Value
Unknown

CVE-2025-22301

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore allows Cross Site Request Forgery.This issue affects MyBookTable Bookstore: from n/a through 3.5.3.
0
Attacker Value
Unknown

CVE-2024-56276

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through 1.9.2.2.
0
Attacker Value
Unknown

CVE-2024-56274

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through 1.2.15.
0
Attacker Value
Unknown

CVE-2024-54030

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free.
0
Attacker Value
Unknown

CVE-2024-47398

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bounds write.
0