Categoria: CVE

CVE-2024-52415 | Skpstorm SK WP Settings Backup Plugin up to 1.0 on WordPress cross-site request forgery

A vulnerability, which was classified as problematic, was found in Skpstorm SK WP Settings Backup Plugin up to 1.0 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. This vulnerability is uniquely identified as CVE-2024-52415. It is possible to initiate the attack remotely. There is no exploit...

Per saperne di più

CVE-2024-52407 | codeSavory BasePress Migration Tools Plugin up to 1.0.0 on WordPress unrestricted upload

A vulnerability was found in codeSavory BasePress Migration Tools Plugin up to 1.0.0 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload. This vulnerability is handled as CVE-2024-52407. The attack may be launched remotely. There is no exploit...

Per saperne di più

CVE-2024-48962 | Apache OFBiz up to 18.12.16 URL Parameter code injection

A vulnerability has been found in Apache OFBiz up to 18.12.16 and classified as critical. This vulnerability affects unknown code of the component URL Parameter Handler. The manipulation leads to code injection. This vulnerability was named CVE-2024-48962. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-41151 | Apache HertzBeat up to 1.6.0 Notice Template deserialization

A vulnerability, which was classified as critical, was found in Apache HertzBeat up to 1.6.0. This affects an unknown part of the component Notice Template Handler. The manipulation leads to deserialization. This vulnerability is uniquely identified as CVE-2024-41151. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più
Caricamento