Show filters
1,963 Total Results
Displaying 111-120 of 1,963
Sort by:
Attacker Value
Unknown

CVE-2024-36513

Disclosure Date: November 12, 2024 (last updated November 15, 2024)
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
Attacker Value
Unknown

CVE-2024-36507

Disclosure Date: November 12, 2024 (last updated November 15, 2024)
A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
Attacker Value
Unknown

CVE-2024-9843

Disclosure Date: November 12, 2024 (last updated January 18, 2025)
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
Attacker Value
Unknown

CVE-2024-9842

Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.
Attacker Value
Unknown

CVE-2024-8539

Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.
Attacker Value
Unknown

CVE-2024-7571

Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
Attacker Value
Unknown

CVE-2023-1932

Disclosure Date: November 07, 2024 (last updated November 07, 2024)
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2024-10454

Disclosure Date: October 31, 2024 (last updated November 01, 2024)
Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to perform click hijacking on victims.
0
Attacker Value
Unknown

CVE-2024-49670

Disclosure Date: October 29, 2024 (last updated November 09, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sam Glover Client Power Tools Portal allows Reflected XSS.This issue affects Client Power Tools Portal: from n/a through 1.8.6.
Attacker Value
Unknown

CVE-2024-50478

Disclosure Date: October 28, 2024 (last updated October 31, 2024)
Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.