Show filters
2,048 Total Results
Displaying 101-110 of 2,048
Sort by:
Attacker Value
Unknown
CVE-2023-47726
Disclosure Date: June 18, 2024 (last updated February 26, 2025)
IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary commands due to improper input validation. IBM X-Force ID: 272087.
0
Attacker Value
Unknown
CVE-2024-22333
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.
0
Attacker Value
Unknown
CVE-2024-0979
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-3559
Disclosure Date: June 12, 2024 (last updated February 26, 2025)
The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-36419
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the issue.
0
Attacker Value
Unknown
CVE-2024-36418
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connectors allows an authenticated user to perform a remote code execution attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
0
Attacker Value
Unknown
CVE-2024-36417
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, an unverified IFrame can be added some some inputs, which could allow for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
0
Attacker Value
Unknown
CVE-2024-36416
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
0
Attacker Value
Unknown
CVE-2024-36415
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in uploaded file verification in products allows for remote code execution. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
0
Attacker Value
Unknown
CVE-2024-36414
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the connectors file verification allows for a server-side request forgery attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
0