Show filters
597 Total Results
Displaying 91-100 of 597
Sort by:
Attacker Value
Unknown

CVE-2022-32756

Disclosure Date: March 22, 2024 (last updated April 02, 2024)
IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 228507.
Attacker Value
Unknown

CVE-2022-32754

Disclosure Date: March 22, 2024 (last updated April 02, 2024)
IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 228445.
Attacker Value
Unknown

CVE-2022-32753

Disclosure Date: March 22, 2024 (last updated April 02, 2024)
IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228444.
Attacker Value
Unknown

CVE-2022-32751

Disclosure Date: March 22, 2024 (last updated April 02, 2024)
IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-Force ID: 228437.
Attacker Value
Unknown

CVE-2024-1071

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown

CVE-2024-2123

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2024-1322

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers to recreate default pages and enable or disable monetization and change map provider.
0
Attacker Value
Unknown

CVE-2024-21381

Disclosure Date: February 13, 2024 (last updated January 12, 2025)
Microsoft Azure Active Directory B2C Spoofing Vulnerability
Attacker Value
Unknown

CVE-2024-1062

Disclosure Date: February 12, 2024 (last updated February 18, 2025)
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
0
Attacker Value
Unknown

CVE-2023-36496

Disclosure Date: February 01, 2024 (last updated February 10, 2024)
Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.