Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown
CVE-2024-38861
Disclosure Date: September 27, 2024 (last updated December 21, 2024)
Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traffic. This issue affects MikroTik: from 2.0.0 through 2.5.5, from 0.4a_mk through 2.0a.
0
Attacker Value
Unknown
CVE-2024-5786
Disclosure Date: June 10, 2024 (last updated June 11, 2024)
Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application to which he is authenticated.
0
Attacker Value
Unknown
CVE-2024-5785
Disclosure Date: June 10, 2024 (last updated June 11, 2024)
Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability could allow an authenticated user to execute commands inside the router by making a POST request to the URL “/boaform/admin/formUserTracert”.
0
Attacker Value
Unknown
CVE-2023-5905
Disclosure Date: January 15, 2024 (last updated January 20, 2024)
The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts.
0
Attacker Value
Unknown
CVE-2023-52129
Disclosure Date: January 05, 2024 (last updated January 12, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.
0
Attacker Value
Unknown
CVE-2023-49163
Disclosure Date: December 18, 2023 (last updated December 23, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.5.
0
Attacker Value
Unknown
CVE-2023-36501
Disclosure Date: July 25, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 9.0.2 versions.
0
Attacker Value
Unknown
CVE-2023-22704
Disclosure Date: March 23, 2023 (last updated December 27, 2023)
Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 8.1.8 versions.
0
Attacker Value
Unknown
CVE-2021-32419
Disclosure Date: February 17, 2023 (last updated October 08, 2023)
An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c.
0
Attacker Value
Unknown
CVE-2018-8062
Disclosure Date: October 23, 2020 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attackers to inject arbitrary web script or HTML via the Service Description parameter while creating a WAN service.
0