Show filters
1,460 Total Results
Displaying 81-90 of 1,460
Sort by:
Attacker Value
Unknown
CVE-2024-9282
Disclosure Date: September 27, 2024 (last updated February 26, 2025)
A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-9281
Disclosure Date: September 27, 2024 (last updated February 26, 2025)
A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-8485
Disclosure Date: September 25, 2024 (last updated February 26, 2025)
The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be updated. This makes it possible for unauthenticated attackers to update arbitrary user's accounts, including their email to a @weixin.com email, which can the be leveraged to reset the password of the user's account, including administrators.
0
Attacker Value
Unknown
CVE-2024-8484
Disclosure Date: September 25, 2024 (last updated February 26, 2025)
The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2024-45104
Disclosure Date: September 13, 2024 (last updated February 26, 2025)
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
0
Attacker Value
Unknown
CVE-2024-45103
Disclosure Date: September 13, 2024 (last updated February 26, 2025)
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
0
Attacker Value
Unknown
CVE-2024-45101
Disclosure Date: September 13, 2024 (last updated February 26, 2025)
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.
0
Attacker Value
Unknown
CVE-2024-45383
Disclosure Date: September 12, 2024 (last updated February 26, 2025)
A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local denial-of-service. An attacker can execute malicious script/application to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2024-6702
Disclosure Date: September 12, 2024 (last updated February 26, 2025)
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
0
Attacker Value
Unknown
CVE-2024-6701
Disclosure Date: September 12, 2024 (last updated February 26, 2025)
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
0