Show filters
325,641 Total Results
Displaying 921-930 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-9148

Disclosure Date: September 25, 2024 (last updated October 01, 2024)
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
Attacker Value
Unknown

CVE-2024-9142

Disclosure Date: September 25, 2024 (last updated September 25, 2024)
External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to File System Calls.This issue affects e-Belediye: before 2.0.642.
0
Attacker Value
Unknown

CVE-2024-9141

Disclosure Date: September 25, 2024 (last updated September 25, 2024)
Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat message. This manipulation occurs when the chat content is intercepted and altered, leading to the execution of the JavaScript payload.
0
Attacker Value
Unknown

CVE-2024-9123

Disclosure Date: September 25, 2024 (last updated September 25, 2024)
Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
0
Attacker Value
Unknown

CVE-2024-9122

Disclosure Date: September 25, 2024 (last updated September 25, 2024)
Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
0
Attacker Value
Unknown

CVE-2024-9121

Disclosure Date: September 25, 2024 (last updated September 25, 2024)
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
0
Attacker Value
Unknown

CVE-2024-9120

Disclosure Date: September 25, 2024 (last updated September 25, 2024)
Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
0
Attacker Value
Unknown

CVE-2024-8942

Disclosure Date: September 25, 2024 (last updated October 01, 2024)
Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.
Attacker Value
Unknown

CVE-2024-8941

Disclosure Date: September 25, 2024 (last updated October 01, 2024)
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application.
Attacker Value
Unknown

CVE-2024-8940

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.