Show filters
104 Total Results
Displaying 11-20 of 104
Sort by:
Attacker Value
Unknown

CVE-2024-5759

Disclosure Date: June 12, 2024 (last updated July 20, 2024)
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges
Attacker Value
Unknown

CVE-2024-1891

Disclosure Date: June 12, 2024 (last updated August 24, 2024)
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.
Attacker Value
Unknown

CVE-2024-2224

Disclosure Date: April 09, 2024 (last updated February 08, 2025)
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1
Attacker Value
Unknown

CVE-2024-2223

Disclosure Date: April 09, 2024 (last updated February 08, 2025)
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:  Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for  Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1
Attacker Value
Unknown

CVE-2024-21330

Disclosure Date: March 12, 2024 (last updated January 12, 2025)
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2023-5451

Disclosure Date: March 04, 2024 (last updated March 05, 2024)
Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS. This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.
0
Attacker Value
Unknown

CVE-2024-1471

Disclosure Date: February 14, 2024 (last updated November 20, 2024)
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.
Attacker Value
Unknown

CVE-2024-1367

Disclosure Date: February 14, 2024 (last updated November 20, 2024)
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
Attacker Value
Unknown

CVE-2024-23617

Disclosure Date: January 26, 2024 (last updated February 01, 2024)
A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.
Attacker Value
Unknown

CVE-2023-1522

Disclosure Date: April 05, 2023 (last updated October 08, 2023)
SQL Injection in the Hardware Inventory report of Security Center 5.11.2.