Show filters
326,776 Total Results
Displaying 1,331-1,340 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-22893

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.
0
Attacker Value
Unknown

CVE-2024-22892

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.
Attacker Value
Unknown

CVE-2024-8316

Disclosure Date: September 25, 2024 (last updated October 03, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
Attacker Value
Unknown

CVE-2024-7679

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Attacker Value
Unknown

CVE-2024-7576

Disclosure Date: September 25, 2024 (last updated October 04, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
Attacker Value
Unknown

CVE-2024-7575

Disclosure Date: September 25, 2024 (last updated October 04, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Attacker Value
Unknown

CVE-2024-6512

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.
Attacker Value
Unknown

CVE-2024-45613

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration. This vulnerability only affects installations where the Block Toolbar plugin is enabled and either the General HTML Support (with a configuration that permits unsafe markup) or the HTML Embed plugin is also enabled. A fix for the problem is available in version 43.1.1. As a workaround, one may disable the block toolbar plugin.
Attacker Value
Unknown

CVE-2024-8546

Disclosure Date: September 25, 2024 (last updated October 03, 2024)
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-4657

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software BAP Automation allows Stored XSS.This issue affects BAP Automation: before 30840.
0