Show filters
671 Total Results
Displaying 101-110 of 671
Sort by:
Attacker Value
Unknown
CVE-2024-27266
Disclosure Date: March 14, 2024 (last updated February 26, 2025)
IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 284566.
0
Attacker Value
Unknown
CVE-2023-43043
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.
0
Attacker Value
Unknown
CVE-2023-38723
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262192.
0
Attacker Value
Unknown
CVE-2023-32335
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075.
0
Attacker Value
Unknown
CVE-2023-38135
Disclosure Date: February 14, 2024 (last updated February 26, 2025)
Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-24202
Disclosure Date: February 08, 2024 (last updated February 26, 2025)
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
0
Attacker Value
Unknown
CVE-2023-7029
Disclosure Date: February 05, 2024 (last updated February 26, 2025)
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including 9.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was partially fixed in version 9.7.6.
0
Attacker Value
Unknown
CVE-2023-32333
Disclosure Date: February 02, 2024 (last updated February 26, 2025)
IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.
0
Attacker Value
Unknown
CVE-2024-23940
Disclosure Date: January 29, 2024 (last updated February 26, 2025)
Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate privileges on an affected system.
0
Attacker Value
Unknown
CVE-2023-33760
Disclosure Date: January 25, 2024 (last updated February 26, 2025)
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.
0