Show filters
1,135 Total Results
Displaying 91-100 of 1,135
Sort by:
Attacker Value
Unknown
CVE-2024-11786
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'continue-with-vipps' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-11024
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset code prior to updating their password. This makes it possible for unauthenticated attackers, with knowledge of a user's email address, to reset the user's password and gain access to their account.
0
Attacker Value
Unknown
CVE-2017-18153
Disclosure Date: November 26, 2024 (last updated January 13, 2025)
A race condition exists in a driver potentially leading to a use-after-free condition.
0
Attacker Value
Unknown
CVE-2024-51829
Disclosure Date: November 19, 2024 (last updated November 20, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Figoli Quinn & Associates Mobile Kiosk allows Stored XSS.This issue affects Mobile Kiosk: from n/a through 1.3.0.
0
Attacker Value
Unknown
CVE-2024-52414
Disclosure Date: November 16, 2024 (last updated November 17, 2024)
Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu allows Object Injection.This issue affects WDES Responsive Mobile Menu: from n/a through 5.3.18.
0
Attacker Value
Unknown
CVE-2024-34681
Disclosure Date: November 06, 2024 (last updated November 06, 2024)
Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local permanent denial of service on Galaxy Watch.
0
Attacker Value
Unknown
CVE-2024-50528
Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.
0
Attacker Value
Unknown
CVE-2024-50527
Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.
0
Attacker Value
Unknown
CVE-2024-38424
Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Memory corruption during GNSS HAL process initialization.
0
Attacker Value
Unknown
CVE-2024-38423
Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Memory corruption while processing GPU page table switch.
0