3.5

CVSS3.1

CVE-2020-9082 -

There is an information disclosure vulnerability in several smartphones. The system has a logic judging error under certain scenario, the attacker should gain the permit to execute commands in ADB mode and then do a series of operation on the phone. Successful exploit could allow the attacker to ga…

πŸ“… Published: Dec. 27, 2024, 9:36 a.m. πŸ”„ Last Modified: Jan. 14, 2025, 5:58 p.m.

3.5

CVSS3.1

CVE-2020-9081 -

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) This vulnerability h…

πŸ“… Published: Dec. 27, 2024, 9:34 a.m. πŸ”„ Last Modified: Jan. 10, 2025, 8:37 p.m.

7.8

CVSS3.1

CVE-2020-9080 -

There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input to exploit this vulnerability. Successful exploitation may lead to local privilege escalation. (Vulnerability ID: HWPSIRT-2020-05272) This vulnerabili…

πŸ“… Published: Dec. 27, 2024, 9:23 a.m. πŸ”„ Last Modified: Jan. 10, 2025, 8:36 p.m.

5.1

CVSS4.0

CVE-2024-12983 - code-projects Hospital Management System Edit Doctor Details Page manage-doctors.php cross site scr…

A vulnerability classified as problematic has been found in code-projects Hospital Management System 1.0. This affects an unknown part of the file /hospital/hms/admin/manage-doctors.php of the component Edit Doctor Details Page. The manipulation of the argument Doctor Name leads to cross site scrip…

πŸ“… Published: Dec. 27, 2024, 6:31 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.1

CVSS4.0

CVE-2024-12982 - PHPGurukul Blood Bank & Donor Management System update-contactinfo.php cross site scripting

A vulnerability was found in PHPGurukul Blood Bank & Donor Management System 2.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /bbdms/admin/update-contactinfo.php. The manipulation of the argument Address leads to cross site scripting. The attac…

πŸ“… Published: Dec. 27, 2024, 6 a.m. πŸ”„ Last Modified: April 3, 2025, 1:08 p.m.

4.8

CVSS3.1

CVE-2024-11921 - Give < 3.19.0 - Reflected XSS

The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Dec. 27, 2024, 6 a.m. πŸ”„ Last Modified: May 14, 2025, 2:43 p.m.

4.3

CVSS3.1

CVE-2024-11842 - DN Shipping by Weight for WooCommerce < 1.2 - Settings Update via CSRF

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“… Published: Dec. 27, 2024, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 2:20 a.m.

4.8

CVSS3.1

CVE-2024-11645 - Float Block <= 1.7 - Admin+ Stored XSS via Widget

The float block WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: Dec. 27, 2024, 6 a.m. πŸ”„ Last Modified: June 12, 2025, 5:03 p.m.

5.9

CVSS3.1

CVE-2024-11644 - WP-SVG <= 0.9 - Contributor+ Stored XSS via Shortcode

The WP-SVG WordPress plugin through 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: Dec. 27, 2024, 6 a.m. πŸ”„ Last Modified: May 14, 2025, 2:49 p.m.

4.8

CVSS3.1

CVE-2024-11605 - WP Publications <= 1.2 - Admin+ Stored XSS

The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite se…

πŸ“… Published: Dec. 27, 2024, 6 a.m. πŸ”„ Last Modified: June 12, 2025, 5:03 p.m.
Total resulsts: 344680
Page 6898 of 34,468
Β« previous page Β» next page
Filters