Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown
CVE-2024-13873
Disclosure Date: February 22, 2025 (last updated February 23, 2025)
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to remove profile photos from users accounts. Please note that this does not officially delete the file.
0
Attacker Value
Unknown
CVE-2023-6978
Disclosure Date: December 04, 2024 (last updated December 21, 2024)
The WP Job Manager – Company Profiles plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'company' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-26201
Disclosure Date: March 12, 2024 (last updated February 26, 2025)
Microsoft Intune Linux Agent Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-0652
Disclosure Date: January 18, 2024 (last updated February 26, 2025)
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file search-visitor.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251378 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-0651
Disclosure Date: January 18, 2024 (last updated February 26, 2025)
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search-visitor.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251377 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-5919
Disclosure Date: November 02, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-244310 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-4832
Disclosure Date: September 14, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Management allows SQL Injection.This issue affects Company Management: before 3072 .
0
Attacker Value
Unknown
CVE-2023-29983
Disclosure Date: May 12, 2023 (last updated February 24, 2025)
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel.
0
Attacker Value
Unknown
CVE-2023-29809
Disclosure Date: May 12, 2023 (last updated February 24, 2025)
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request.
0
Attacker Value
Unknown
CVE-2023-29808
Disclosure Date: May 12, 2023 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code.
0