Show filters
65 Total Results
Displaying 1-10 of 65
Sort by:
Attacker Value
Unknown
CVE-2024-13533
Disclosure Date: February 19, 2025 (last updated February 20, 2025)
The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2024-25571
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
Improper input validation in some Intel(R) SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to potentially enable denial of service via local access.
0
Attacker Value
Unknown
CVE-2025-0220
Disclosure Date: January 05, 2025 (last updated January 07, 2025)
A vulnerability, which was classified as problematic, was found in Trimble SPS851 488.01. This affects an unknown part of the component Ethernet Configuration Menu. The manipulation of the argument Hostname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2025-0219
Disclosure Date: January 05, 2025 (last updated January 05, 2025)
A vulnerability, which was classified as problematic, has been found in Trimble SPS851 488.01. Affected by this issue is some unknown functionality of the component Receiver Status Identity Tab. The manipulation of the argument System Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-47921
Disclosure Date: December 30, 2024 (last updated January 02, 2025)
Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm
0
Attacker Value
Unknown
CVE-2024-32811
Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Insertion of Sensitive Information into Log File vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affects USPS Shipping for WooCommerce – Live Rates: from n/a through 1.9.4.
0
Attacker Value
Unknown
CVE-2024-31943
Disclosure Date: April 10, 2024 (last updated April 11, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affects USPS Shipping for WooCommerce – Live Rates: from n/a through 1.9.2.
0
Attacker Value
Unknown
CVE-2023-35191
Disclosure Date: March 14, 2024 (last updated April 01, 2024)
Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially enable denial of service via network access.
0
Attacker Value
Unknown
CVE-2022-43855
Disclosure Date: March 08, 2024 (last updated January 12, 2025)
IBM SPSS Statistics 26.0, 27.0.1, and 28.0 could allow a local user to create multiple files that could exhaust the file handles capacity and cause a denial of service. IBM X-Force ID: 230235.
0
Attacker Value
Unknown
CVE-2023-29153
Disclosure Date: February 14, 2024 (last updated February 15, 2024)
Uncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentially enable denial of service via network access.
0