Show filters
90 Total Results
Displaying 1-10 of 90
Sort by:
Attacker Value
Unknown

CVE-2024-38794

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in MediaRon LLC Custom Query Blocks allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Custom Query Blocks: from n/a through 5.2.0.
0
Attacker Value
Unknown

CVE-2024-41930

Disclosure Date: September 27, 2024 (last updated September 27, 2024)
Cross-site scripting vulnerability exists in MF Teacher Performance Management System version 6. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.
0
Attacker Value
Unknown

CVE-2024-44059

Disclosure Date: September 15, 2024 (last updated September 28, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MediaRon LLC Custom Query Blocks allows Stored XSS.This issue affects Custom Query Blocks: from n/a through 5.3.1.
Attacker Value
Unknown

CVE-2024-33566

Disclosure Date: April 29, 2024 (last updated April 29, 2024)
Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.
0
Attacker Value
Unknown

CVE-2024-25903

Disclosure Date: March 17, 2024 (last updated April 01, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: from n/a through 22.7.
0
Attacker Value
Unknown

CVE-2023-45364

Disclosure Date: October 09, 2023 (last updated October 13, 2023)
An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.
Attacker Value
Unknown

CVE-2023-45363

Disclosure Date: October 09, 2023 (last updated October 13, 2023)
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
Attacker Value
Unknown

CVE-2023-32829

Disclosure Date: October 02, 2023 (last updated October 08, 2023)
In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07713478; Issue ID: ALPS07713478.
Attacker Value
Unknown

CVE-2023-32820

Disclosure Date: October 02, 2023 (last updated October 08, 2023)
In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.
Attacker Value
Unknown

CVE-2023-3550

Disclosure Date: September 25, 2023 (last updated February 14, 2025)
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.
0