Show filters
349 Total Results
Displaying 91-100 of 349
Sort by:
Attacker Value
Unknown
CVE-2024-1742
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.
0
Attacker Value
Unknown
CVE-2024-0638
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.
0
Attacker Value
Unknown
CVE-2024-25592
Disclosure Date: March 15, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Broken Link Checker allows Stored XSS.This issue affects Broken Link Checker: from n/a through 2.2.3.
0
Attacker Value
Unknown
CVE-2024-0670
Disclosure Date: March 11, 2024 (last updated February 26, 2025)
Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges
0
Attacker Value
Unknown
CVE-2024-28153
Disclosure Date: March 06, 2024 (last updated February 26, 2025)
Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2024-1977
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist points in version 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2024-25925
Disclosure Date: February 26, 2024 (last updated February 26, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12.
0
Attacker Value
Unknown
CVE-2024-24885
Disclosure Date: February 08, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lê Văn Toản Woocommerce Vietnam Checkout allows Stored XSS.This issue affects Woocommerce Vietnam Checkout: from n/a through 2.0.7.
0
Attacker Value
Unknown
CVE-2024-22143
Disclosure Date: January 31, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9.17.
0
Attacker Value
Unknown
CVE-2024-22380
Disclosure Date: January 24, 2024 (last updated February 26, 2025)
Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
0