Show filters
597 Total Results
Displaying 91-100 of 597
Sort by:
Attacker Value
Unknown

CVE-2024-4272

Disclosure Date: July 13, 2024 (last updated July 13, 2024)
The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
0
Attacker Value
Unknown

CVE-2024-6409

Disclosure Date: July 08, 2024 (last updated February 26, 2025)
A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.
0
Attacker Value
Unknown

CVE-2024-4467

Disclosure Date: July 02, 2024 (last updated February 26, 2025)
A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.
0
Attacker Value
Unknown

CVE-2024-3633

Disclosure Date: June 26, 2024 (last updated June 26, 2024)
The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
0
Attacker Value
Unknown

CVE-2024-5953

Disclosure Date: June 18, 2024 (last updated February 26, 2025)
A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.
0
Attacker Value
Unknown

CVE-2023-51537

Disclosure Date: June 12, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.
Attacker Value
Unknown

CVE-2023-4727

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.
0
Attacker Value
Unknown

CVE-2024-35741

Disclosure Date: June 10, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.
Attacker Value
Unknown

CVE-2024-32081

Disclosure Date: June 09, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.
Attacker Value
Unknown

CVE-2024-24716

Disclosure Date: June 09, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.6.