6.5

CVSS3.1

CVE-2024-34683 - Unrestricted file upload in SAP Document Builder (HTTP service)

An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victim’s browser.

📅 Published: June 11, 2024, 2:08 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:19 a.m.

6.5

CVSS3.1

CVE-2024-33001 - Denial of service (DOS) in SAP NetWeaver and ABAP platform

SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of this Denial of Service vulnerability might be long response delays and service interruptions, thus degrading the service quality experienced by legitima…

📅 Published: June 11, 2024, 2:05 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:16 a.m.

7.5

CVSS3.1

CVE-2024-34688 - Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)

Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability …

📅 Published: June 11, 2024, 2:02 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:19 a.m.

5.3

CVSS3.1

CVE-2024-2473 - WPS Hide Login <= 1.9.15.2 - Login Page Disclosure

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may ha…

📅 Published: June 11, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

4.4

CVSS3.1

CVE-2024-0653 - Custom Field Template <= 2.6.1 - Authenticated (Admin+) Stored Cross-Site Scritping

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss…

📅 Published: June 11, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 5:11 p.m.

4.3

CVSS3.1

CVE-2023-6748 - Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Information Exposure

The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. This makes it possible for authenticated attackers with contributor access and above, to extract sensitive data including arbitrary pos…

📅 Published: June 11, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 5:03 p.m.

6.4

CVSS3.1

CVE-2024-0627 - Custom Field Template <= 2.6.1 - Authenticated(Constibutor+) Stored Cross-Site Scripting via Custom…

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom field name column in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied custom fields. This makes it possible for aut…

📅 Published: June 11, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 6:18 p.m.

6.4

CVSS3.1

CVE-2024-5090 - SiteOrigin Widgets Bundle <= 1.61.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOrigin Blog Widget in all versions up to, and including, 1.61.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut…

📅 Published: June 11, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 5:19 p.m.

6.4

CVSS3.1

CVE-2023-6745 - Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortc…

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cpt' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied post meta. This makes it possible for authenticated at…

📅 Published: June 11, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

5

CVSS3.1

CVE-2024-37178 - Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation

SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can exploit resources beyond the vulnerable component. On successful exploitation, an attacker can …

📅 Published: June 11, 2024, 2 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9511 of 34,919
« previous page » next page
Filters