Show filters
325,749 Total Results
Displaying 1,121-1,130 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-0004

Disclosure Date: September 23, 2024 (last updated September 28, 2024)
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
Attacker Value
Unknown

CVE-2024-0003

Disclosure Date: September 23, 2024 (last updated September 28, 2024)
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
Attacker Value
Unknown

CVE-2024-0002

Disclosure Date: September 23, 2024 (last updated September 28, 2024)
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
Attacker Value
Unknown

CVE-2024-0001

Disclosure Date: September 23, 2024 (last updated September 28, 2024)
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
Attacker Value
Unknown

CVE-2023-46948

Disclosure Date: September 23, 2024 (last updated September 24, 2024)
A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.
0
Attacker Value
Unknown

CVE-2024-9014

Disclosure Date: September 23, 2024 (last updated September 24, 2024)
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
0
Attacker Value
Unknown

CVE-2024-40442

Disclosure Date: September 23, 2024 (last updated September 24, 2024)
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.
0
Attacker Value
Unknown

CVE-2024-40441

Disclosure Date: September 23, 2024 (last updated September 24, 2024)
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.
0
Attacker Value
Unknown

CVE-2024-47069

Disclosure Date: September 23, 2024 (last updated October 01, 2024)
Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability.
Attacker Value
Unknown

CVE-2024-47068

Disclosure Date: September 23, 2024 (last updated October 01, 2024)
Rollup is a module bundler for JavaScript. Versions prior to 3.29.5 and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from `import.meta` (e.g., `import.meta.url`) in `cjs`/`umd`/`iife` format. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an `img` tag with an unsanitized `name` attribute) are present. Versions 3.29.5 and 4.22.4 contain a patch for the vulnerability.