Show filters
134 Total Results
Displaying 1-10 of 134
Sort by:
Attacker Value
Unknown
CVE-2019-3568
Disclosure Date: May 14, 2019 (last updated July 03, 2024)
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
1
Attacker Value
Unknown
CVE-2025-26768
Disclosure Date: February 16, 2025 (last updated February 17, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in what3words what3words Address Field allows Stored XSS. This issue affects what3words Address Field: from n/a through 4.0.15.
0
Attacker Value
Unknown
CVE-2025-25138
Disclosure Date: February 07, 2025 (last updated February 07, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Rishi On Page SEO + Whatsapp Chat Button allows Stored XSS. This issue affects On Page SEO + Whatsapp Chat Button: from n/a through 2.0.0.
0
Attacker Value
Unknown
CVE-2024-11686
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-12108
Disclosure Date: December 31, 2024 (last updated January 13, 2025)
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
0
Attacker Value
Unknown
CVE-2024-12106
Disclosure Date: December 31, 2024 (last updated January 13, 2025)
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
0
Attacker Value
Unknown
CVE-2024-12105
Disclosure Date: December 31, 2024 (last updated January 13, 2025)
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.
0
Attacker Value
Unknown
CVE-2024-55987
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ritesh Sanap Advanced What should we write next about allows SQL Injection.This issue affects Advanced What should we write next about: from n/a through 1.0.3.
0
Attacker Value
Unknown
CVE-2024-8785
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.
0
Attacker Value
Unknown
CVE-2024-46909
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
0