Show filters
294 Total Results
Displaying 11-20 of 294
Sort by:
Attacker Value
Unknown

CVE-2024-6739

Disclosure Date: July 15, 2024 (last updated February 26, 2025)
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
Attacker Value
Unknown

CVE-2024-6355

Disclosure Date: June 26, 2024 (last updated February 26, 2025)
A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /status/product_info/. The manipulation of the argument product_info leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269755. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-6176

Disclosure Date: June 20, 2024 (last updated February 26, 2025)
Allocation of Resources Without Limits or Throttling vulnerability in LG Electronics LG SuperSign CMS allows Port Scanning.This issue affects LG SuperSign CMS: from 4.1.3 before < 4.3.1.
0
Attacker Value
Unknown

CVE-2024-6108

Disclosure Date: June 18, 2024 (last updated February 26, 2025)
A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been classified as problematic. Affected is an unknown function of the file /vood/cgi-bin/vood_view.cgi?act=index&lang=EN# of the component Login. The manipulation of the argument errmsg leads to basic cross site scripting. It is possible to launch the attack remotely. VDB-268854 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-6048

Disclosure Date: June 17, 2024 (last updated February 26, 2025)
Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system commands and execute them on the remote server.
0
Attacker Value
Unknown

CVE-2024-5184

Disclosure Date: June 05, 2024 (last updated February 26, 2025)
The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service logic. Attackers can exploit the issue by forcing the AI service to leak the standard hard-coded system prompts and/or execute unwanted prompts. When engaging with EmailGPT by submitting a malicious prompt that requests harmful information, the system will respond by providing the requested data. This vulnerability can be exploited by any individual with access to the service.
Attacker Value
Unknown

CVE-2024-32470

Disclosure Date: April 18, 2024 (last updated February 26, 2025)
Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was introduced in v3.57.2 and immediately fixed in v3.57.4.
0
Attacker Value
Unknown

CVE-2024-32466

Disclosure Date: April 18, 2024 (last updated February 26, 2025)
Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/translations` endpoints, translation data was returned even when API key was missing `translation.view` scope. However, it was impossible to fetch the data when user was missing this scope. So this is only relevant for API keys generated by users permitted to `translation.view`. This vulnerability is fixed in v3.57.2
0
Attacker Value
Unknown

CVE-2024-2863

Disclosure Date: March 25, 2024 (last updated February 26, 2025)
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
0
Attacker Value
Unknown

CVE-2024-2862

Disclosure Date: March 25, 2024 (last updated February 26, 2025)
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
0