Show filters
335,494 Total Results
Displaying 751-760 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-10861

Disclosure Date: November 16, 2024 (last updated November 16, 2024)
The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to update the 'ays_pb_upgrade_plugin' option with arbitrary data.
Attacker Value
Unknown

CVE-2024-10795

Disclosure Date: November 16, 2024 (last updated November 16, 2024)
The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created via Elementor that they should not have access to.
Attacker Value
Unknown

CVE-2024-10786

Disclosure Date: November 16, 2024 (last updated November 16, 2024)
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear user caches.
Attacker Value
Unknown

CVE-2024-11263

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols.
0
Attacker Value
Unknown

CVE-2024-11262

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affected by this vulnerability is the function main of the component View All Student Marks. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown

CVE-2024-9500

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to insecure privilege management.
0
Attacker Value
Unknown

CVE-2024-51765

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
0
Attacker Value
Unknown

CVE-2024-51764

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
0
Attacker Value
Unknown

CVE-2024-50983

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections.
0
Attacker Value
Unknown

CVE-2024-38370

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
0