Categoria: CVE

CVE-2024-12117 | Stackable Plugin up to 3.13.11 on WordPress Gutenberg Block cross site scripting

A vulnerability, which was classified as problematic, was found in Stackable Plugin up to 3.13.11 on WordPress. This affects an unknown part of the component Gutenberg Block Handler. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-12117. It is possible to initiate the attack remotely. There is no exploit...

Per saperne di più

CVE-2025-23195 | Apache Ambari up to 2.7.8 DocumentBuilderFactory xml external entity reference

A vulnerability was found in Apache Ambari up to 2.7.8 and classified as problematic. Affected by this issue is the function DocumentBuilderFactory. The manipulation leads to xml external entity reference. This vulnerability is handled as CVE-2025-23195. The attack can only be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-51941 | Apache Ambari up to 2.7.8 Ambari Metrics/AMS Alerts special elements into a different plane (special element injection)

A vulnerability has been found in Apache Ambari up to 2.7.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Ambari Metrics/AMS Alerts. The manipulation leads to failure to sanitize special elements into a different plane (special element injection). This vulnerability is known as CVE-2024-51941. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2025-21520 | Oracle MySQL Server up to 7.6.32/8.0.40/8.4.3/9.1.0 Options improper authorization

A vulnerability classified as problematic has been found in Oracle MySQL Server up to 7.6.32/8.0.40/8.4.3/9.1.0. Affected is an unknown function of the component Options. The manipulation leads to improper authorization. This vulnerability is traded as CVE-2025-21520. The attack needs to be approached locally. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2025-21551 | Oracle Solaris 11 File System improper authorization

A vulnerability was found in Oracle Solaris 11. It has been rated as critical. This issue affects some unknown processing of the component File System. The manipulation leads to improper authorization. The identification of this vulnerability is CVE-2025-21551. It is possible to launch the attack on the local host. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più
Caricamento