Show filters
234 Total Results
Displaying 11-20 of 234
Sort by:
Attacker Value
Unknown

CVE-2025-0055

Disclosure Date: January 14, 2025 (last updated January 14, 2025)
SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application.
0
Attacker Value
Unknown

CVE-2025-21618

Disclosure Date: January 06, 2025 (last updated January 07, 2025)
NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including browsers in incognito mode. This vulnerability is fixed in 2.9.1.
0
Attacker Value
Unknown

CVE-2023-50876

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Molongui Molongui allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Molongui: from n/a through 4.7.3.
0
Attacker Value
Unknown

CVE-2024-51850

Disclosure Date: November 19, 2024 (last updated November 20, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bchristopeit WoW Guild Armory Roster allows Stored XSS.This issue affects WoW Guild Armory Roster: from n/a through 0.5.5.
0
Attacker Value
Unknown

CVE-2024-27461

Disclosure Date: August 14, 2024 (last updated September 07, 2024)
Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service via local access.
Attacker Value
Unknown

CVE-2024-39600

Disclosure Date: July 09, 2024 (last updated January 23, 2025)
Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which might allow an attacker to get hold of the password and impersonate the affected user. As a result, it has a high impact on the confidentiality but there is no impact on the integrity and availability.
Attacker Value
Unknown

CVE-2024-1305

Disclosure Date: July 08, 2024 (last updated July 09, 2024)
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space
0
Attacker Value
Unknown

CVE-2024-32005

Disclosure Date: April 12, 2024 (last updated April 13, 2024)
NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component when requesting resource files under the `/_nicegui/{__version__}/resources/{key}/{path:path}` route. As a result any file on the backend filesystem which the web server has access to can be read by an attacker with access to the NiceUI leaflet website. This vulnerability has been addressed in version 1.4.21. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown

CVE-2024-30507

Disclosure Date: March 29, 2024 (last updated January 05, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.
0
Attacker Value
Unknown

CVE-2024-29764

Disclosure Date: March 27, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molongui allows Stored XSS.This issue affects Molongui: from n/a through 4.7.7.
0