U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
There are 231,666 matching records.
Displaying matches 241 through 260.
Vuln ID Summary CVSS Severity
CVE-2024-1204

The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.

Published: April 15, 2024; 1:15:14 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-0902

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Published: April 15, 2024; 1:15:14 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-0399

The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.

Published: April 15, 2024; 1:15:14 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-7201

The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

Published: April 15, 2024; 1:15:14 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-6067

The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Published: April 15, 2024; 1:15:13 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-3778

The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with dangerous type containing malicious code.

Published: April 15, 2024; 12:15:16 AM -0400
V3.1: 7.2 HIGH
V2.0:(not available)
CVE-2024-3777

The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.

Published: April 15, 2024; 12:15:16 AM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2024-3776

The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.

Published: April 15, 2024; 12:15:16 AM -0400
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2024-3775

aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.

Published: April 15, 2024; 12:15:16 AM -0400
V3.1: 5.3 MEDIUM
V2.0:(not available)
CVE-2024-3769

A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /login.php. The manipulation of the argument id/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260616.

Published: April 15, 2024; 12:15:15 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-3768

A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the file search.php. The manipulation of the argument searchtitle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260615.

Published: April 15, 2024; 12:15:15 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-3767

A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-260614 is the identifier assigned to this vulnerability.

Published: April 15, 2024; 12:15:15 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-1655

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.

Published: April 15, 2024; 12:15:14 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-3774

aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.

Published: April 14, 2024; 11:16:08 PM -0400
V3.1: 5.3 MEDIUM
V2.0:(not available)
CVE-2024-3772

Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

Published: April 14, 2024; 11:16:07 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-3766

A vulnerability, which was classified as problematic, has been found in slowlyo OwlAdmin up to 3.5.7. Affected by this issue is some unknown functionality of the file /admin-api/upload_image of the component Image File Upload. The manipulation of the argument file leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-260606 is the identifier assigned to this vulnerability.

Published: April 14, 2024; 8:15:14 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-29844

Default credentials on the Web Interface of Evolution Controller 2.x (123 and 123) allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password.

Published: April 14, 2024; 8:15:14 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-29843

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all users and their access levels

Published: April 14, 2024; 8:15:14 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-29842

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the abacard field of any user

Published: April 14, 2024; 8:15:14 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-29841

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user

Published: April 14, 2024; 8:15:13 PM -0400
V3.x:(not available)
V2.0:(not available)