Show filters
1,815 Total Results
Displaying 91-100 of 1,815
Sort by:
Attacker Value
Unknown

CVE-2024-5030

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack
0
Attacker Value
Unknown

CVE-2024-10311

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin settings and log in as any existing user on the site, such as an administrator.
Attacker Value
Unknown

CVE-2024-49042

Disclosure Date: November 12, 2024 (last updated January 13, 2025)
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2024-43613

Disclosure Date: November 12, 2024 (last updated January 13, 2025)
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2024-51710

Disclosure Date: November 09, 2024 (last updated November 10, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Minerva Infotech Responsive Data Table allows Reflected XSS.This issue affects Responsive Data Table: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2024-10876

Disclosure Date: November 09, 2024 (last updated November 09, 2024)
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.8.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-8323

Disclosure Date: November 06, 2024 (last updated November 09, 2024)
The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-5578

Disclosure Date: November 05, 2024 (last updated November 07, 2024)
The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2024-37510

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.
0
Attacker Value
Unknown

CVE-2024-37506

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.
0