Show filters
3,839 Total Results
Displaying 241-250 of 3,839
Sort by:
Attacker Value
Unknown
CVE-2024-37306
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into visiting a malicious URL, they can initiate a dataset export or a backup from a project, task or job that the victim user has permission to export into a cloud storage that the victim user has access to. The name of the resulting file can be chosen by the attacker. This implies that the attacker can overwrite arbitrary files in any cloud storage that the victim can access and, if the attacker has read access to the cloud storage used in the attack, they can obtain media files, annotations, settings and other information from any projects, tasks or jobs that the victim has permission to export. Version 2.14.3 contains a fix for the issue. No known workarounds are available.
0
Attacker Value
Unknown
CVE-2024-38293
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
0
Attacker Value
Unknown
CVE-2023-47845
Disclosure Date: June 12, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.
0
Attacker Value
Unknown
CVE-2024-35207
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.
0
Attacker Value
Unknown
CVE-2024-27817
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.
0
Attacker Value
Unknown
CVE-2024-31612
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator information.
0
Attacker Value
Unknown
CVE-2024-31613
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."
0
Attacker Value
Unknown
CVE-2024-4403
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows attackers to trick users into performing unintended actions, such as resetting the program without their knowledge, by sending specially crafted CSRF forms. This issue affects the installation process, including the installation of Binding zoo and Models zoo, by unexpectedly resetting programs. The vulnerability is due to the lack of CSRF protection in the affected function.
0
Attacker Value
Unknown
CVE-2024-5786
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application to which he is authenticated.
0
Attacker Value
Unknown
CVE-2024-4328
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerability arises from the use of a GET request to clear personality files list, which lacks proper CSRF protection. This flaw allows attackers to trick users into performing actions without their consent, such as deleting important files on the system. The issue is present in the application's handling of requests, making it susceptible to CSRF attacks that could lead to unauthorized actions being performed on behalf of the user.
0