Show filters
922 Total Results
Displaying 81-90 of 922
Sort by:
Attacker Value
Unknown

CVE-2024-10861

Disclosure Date: November 16, 2024 (last updated January 06, 2025)
The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to update the 'ays_pb_upgrade_plugin' option with arbitrary data.
0
Attacker Value
Unknown

CVE-2022-20853

Disclosure Date: November 15, 2024 (last updated January 06, 2025)
A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the REST API to follow a crafted link. A successful exploit could allow the attacker to cause the affected system to reload. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. 
0
Attacker Value
Unknown

CVE-2022-20814

Disclosure Date: November 15, 2024 (last updated January 06, 2025)
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.  The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified Communications Manager device. An attacker could exploit this vulnerability by using a man-in-the-middle technique to intercept the traffic between the devices, and then using a self-signed certificate to impersonate the endpoint. A successful exploit could allow the attacker to view the intercepted traffic in clear text or alter the contents of the traffic. Note: Cisco Expressway-E is not affected by this vulnerability.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
0
Attacker Value
Unknown

CVE-2024-51781

Disclosure Date: November 09, 2024 (last updated November 09, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Loop Now Technologies, Inc. Firework Shoppable Live Video allows Reflected XSS.This issue affects Firework Shoppable Live Video: from n/a through 6.3.
0
Attacker Value
Unknown

CVE-2024-10535

Disclosure Date: November 06, 2024 (last updated November 09, 2024)
The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function in all versions up to, and including, 1.31. This makes it possible for unauthenticated attackers to delete thumbnails in the video-wc-gallery-thumb directory.
Attacker Value
Unknown

CVE-2024-49404

Disclosure Date: November 06, 2024 (last updated November 13, 2024)
Improper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows physical attackers to access video file of other users.
Attacker Value
Unknown

CVE-2024-38424

Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Memory corruption during GNSS HAL process initialization.
Attacker Value
Unknown

CVE-2024-38423

Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Memory corruption while processing GPU page table switch.
Attacker Value
Unknown

CVE-2024-38422

Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Attacker Value
Unknown

CVE-2024-38421

Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Memory corruption while processing GPU commands.