Show filters
2,285 Total Results
Displaying 91-100 of 2,285
Sort by:
Attacker Value
Unknown
CVE-2023-1932
Disclosure Date: November 07, 2024 (last updated February 27, 2025)
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2024-9902
Disclosure Date: November 06, 2024 (last updated February 26, 2025)
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.
0
Attacker Value
Unknown
CVE-2024-10543
Disclosure Date: November 06, 2024 (last updated February 27, 2025)
The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hypeanimations_getcontent function in all versions up to, and including, 1.9.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve animation information.
0
Attacker Value
Unknown
CVE-2024-50419
Disclosure Date: October 30, 2024 (last updated February 27, 2025)
Incorrect Authorization vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift – animation and page builder blocks: from n/a through 9.7.
0
Attacker Value
Unknown
CVE-2024-50506
Disclosure Date: October 30, 2024 (last updated February 26, 2025)
Incorrect Privilege Assignment vulnerability in Azexo Marketing Automation by AZEXO allows Privilege Escalation.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.
0
Attacker Value
Unknown
CVE-2024-50480
Disclosure Date: October 29, 2024 (last updated February 26, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO allows Upload a Web Shell to a Web Server.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.
0
Attacker Value
Unknown
CVE-2024-47328
Disclosure Date: October 21, 2024 (last updated February 26, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Automation By Autonami allows SQL Injection.This issue affects Automation By Autonami: from n/a through 3.1.2.
0
Attacker Value
Unknown
CVE-2024-4692
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels.
Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate Service Virtualization server names.
This issue affects OpenText Application Automation Tools: 24.1.0 and below.
0
Attacker Value
Unknown
CVE-2024-4690
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
0
Attacker Value
Unknown
CVE-2024-4211
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels.
Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate ALM server names, usernames and client IDs configured to be used with ALM servers.
This issue affects OpenText Application Automation Tools: 24.1.0 and below.
0