Show filters
159 Total Results
Displaying 11-20 of 159
Sort by:
Attacker Value
Unknown

CVE-2024-4132

Disclosure Date: October 11, 2024 (last updated October 18, 2024)
A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.
Attacker Value
Unknown

CVE-2024-7502

Disclosure Date: August 06, 2024 (last updated August 13, 2024)
A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2024-7358

Disclosure Date: August 01, 2024 (last updated August 02, 2024)
A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of the component Installation. The manipulation leads to creation of temporary file with insecure permissions. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-273337 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but was not able to provide a technical response in time.
0
Attacker Value
Unknown

CVE-2024-29801

Disclosure Date: March 27, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Petri Damstén Fullscreen Galleria allows Stored XSS.This issue affects Fullscreen Galleria: from n/a through 1.6.11.
0
Attacker Value
Unknown

CVE-2023-6501

Disclosure Date: February 12, 2024 (last updated October 10, 2024)
The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Attacker Value
Unknown

CVE-2023-47257

Disclosure Date: February 01, 2024 (last updated February 08, 2024)
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
Attacker Value
Unknown

CVE-2023-47256

Disclosure Date: February 01, 2024 (last updated February 08, 2024)
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
Attacker Value
Unknown

CVE-2023-6149

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access to configure or edit jobs to utilize the plugin and configure potential a rouge endpoint via which it was possible to control response for certain request which could be injected with XXE payloads leading to XXE while processing the response data
Attacker Value
Unknown

CVE-2023-47182

Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions.
Attacker Value
Unknown

CVE-2023-5243

Disclosure Date: October 31, 2023 (last updated November 09, 2023)
The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).