Show filters
3,839 Total Results
Displaying 241-250 of 3,839
Sort by:
Attacker Value
Unknown

CVE-2024-37306

Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into visiting a malicious URL, they can initiate a dataset export or a backup from a project, task or job that the victim user has permission to export into a cloud storage that the victim user has access to. The name of the resulting file can be chosen by the attacker. This implies that the attacker can overwrite arbitrary files in any cloud storage that the victim can access and, if the attacker has read access to the cloud storage used in the attack, they can obtain media files, annotations, settings and other information from any projects, tasks or jobs that the victim has permission to export. Version 2.14.3 contains a fix for the issue. No known workarounds are available.
Attacker Value
Unknown

CVE-2024-38293

Disclosure Date: June 13, 2024 (last updated February 26, 2025)
ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
0
Attacker Value
Unknown

CVE-2023-47845

Disclosure Date: June 12, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.
0
Attacker Value
Unknown

CVE-2024-35207

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.
Attacker Value
Unknown

CVE-2024-27817

Disclosure Date: June 10, 2024 (last updated February 26, 2025)
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.
Attacker Value
Unknown

CVE-2024-31612

Disclosure Date: June 10, 2024 (last updated February 26, 2025)
Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator information.
Attacker Value
Unknown

CVE-2024-31613

Disclosure Date: June 10, 2024 (last updated February 26, 2025)
BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."
0
Attacker Value
Unknown

CVE-2024-4403

Disclosure Date: June 10, 2024 (last updated February 26, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows attackers to trick users into performing unintended actions, such as resetting the program without their knowledge, by sending specially crafted CSRF forms. This issue affects the installation process, including the installation of Binding zoo and Models zoo, by unexpectedly resetting programs. The vulnerability is due to the lack of CSRF protection in the affected function.
0
Attacker Value
Unknown

CVE-2024-5786

Disclosure Date: June 10, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application to which he is authenticated.
0
Attacker Value
Unknown

CVE-2024-4328

Disclosure Date: June 10, 2024 (last updated February 26, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerability arises from the use of a GET request to clear personality files list, which lacks proper CSRF protection. This flaw allows attackers to trick users into performing actions without their consent, such as deleting important files on the system. The issue is present in the application's handling of requests, making it susceptible to CSRF attacks that could lead to unauthorized actions being performed on behalf of the user.