Aggregator
CVE-2007-4737 | SpeedTech PHP Library stphptabtitle.php STPHPLIB_DIR code injection (EDB-4358 / XFDB-36417)
11 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in SpeedTech PHP Library. This issue affects some unknown processing in the library STPHPLIB_DIR of the file stphptabtitle.php. The manipulation of the argument STPHPLIB_DIR leads to code injection.
The identification of this vulnerability is CVE-2007-4737. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
《默杀》观后
11 months 2 weeks ago
这可能是第一次未看到彩蛋而心满意足
CVE-2014-7403 | NZHondas.com 3.6.14 X.509 Certificate cryptographic issues (VU#582497)
11 months 2 weeks ago
A vulnerability classified as critical has been found in NZHondas.com 3.6.14. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7403. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2016-4147 | Adobe Flash Player up to 21.0.0.242 privileges management (MS16-083 / Nessus ID 91671)
11 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Adobe Flash Player up to 21.0.0.242. This affects an unknown part. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2016-4147. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-41587 | DrayTek Vigor310 up to 4.3.2.6 Login Page Greeting Message cross site scripting
11 months 2 weeks ago
A vulnerability was found in DrayTek Vigor310 up to 4.3.2.6. It has been classified as problematic. This affects an unknown part of the component Login Page Greeting Message. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-41587. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-44207 | Apple iOS/iPadOS up to 18.0 Audio Message information disclosure (ID 121373)
11 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Apple iOS and iPadOS up to 18.0. This affects an unknown part of the component Audio Message Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-44207. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44204 | Apple iOS/iPadOS up to 18.0 VoiceOver information disclosure (ID 121373)
11 months 2 weeks ago
A vulnerability was found in Apple iOS and iPadOS up to 18.0. It has been classified as problematic. Affected is an unknown function of the component VoiceOver. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-44204. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9345 | Product Delivery Date for WooCommerce Lite Plugin up to 2.7.3 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability classified as problematic has been found in Product Delivery Date for WooCommerce Lite Plugin up to 2.7.3 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-9345. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8802 | Clio Grow Plugin up to 1.0.2 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability was found in Clio Grow Plugin up to 1.0.2 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-8802. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9237 | Fish and Ships Plugin up to 1.5.9 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability was found in Fish and Ships Plugin up to 1.5.9 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-9237. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9353 | Popularis Extra Plugin up to 1.2.6 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability was found in Popularis Extra Plugin up to 1.2.6 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-9353. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-8520 | Ultimate Member Plugin up to 2.8.6 on WordPress Membership Status cross-site request forgery
11 months 2 weeks ago
A vulnerability classified as problematic has been found in Ultimate Member Plugin up to 2.8.6 on WordPress. This affects an unknown part of the component Membership Status Handler. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-8520. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-9204 | Smart Custom 404 Error Page Plugin up to 11.4.7 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability classified as problematic was found in Smart Custom 404 Error Page Plugin up to 11.4.7 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-9204. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8519 | Ultimate Member Plugin up to 2.8.6 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Ultimate Member Plugin up to 2.8.6 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-8519. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9349 | Auto Amazon Links Plugin up to 5.4.2 on WordPress cross site scripting
11 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Auto Amazon Links Plugin up to 5.4.2 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-9349. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8733 | HP One Agent Software untrusted search path
11 months 2 weeks ago
A vulnerability was found in HP One Agent Software. It has been classified as critical. Affected is an unknown function. The manipulation leads to untrusted search path.
This vulnerability is traded as CVE-2024-8733. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46977 | OpenC3 cosmos up to 5.18.x LocalMode open_local_file path traversal (GHSA-8jxr-mccc-mwg8)
11 months 2 weeks ago
A vulnerability has been found in OpenC3 cosmos up to 5.18.x and classified as critical. Affected by this vulnerability is the function open_local_file of the component LocalMode. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-46977. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43795 | OpenC3 cosmos Open Source Edition up to 5.18.x cross site scripting (GHSA-vfj8-5pj7-2f9g)
11 months 2 weeks ago
A vulnerability was found in OpenC3 cosmos Open Source Edition up to 5.18.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-43795. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45965 | Contao up to 5.4.1 SVG File cross site scripting
11 months 2 weeks ago
A vulnerability was found in Contao up to 5.4.1. It has been rated as problematic. This issue affects some unknown processing of the component SVG File Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-45965. The attack may be initiated remotely. There is no exploit available.
vuldb.com