Show filters
524 Total Results
Displaying 111-120 of 524
Sort by:
Attacker Value
Unknown

CVE-2024-0166

Disclosure Date: February 12, 2024 (last updated February 16, 2024)
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.
Attacker Value
Unknown

CVE-2024-0165

Disclosure Date: February 12, 2024 (last updated February 16, 2024)
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.
Attacker Value
Unknown

CVE-2024-0164

Disclosure Date: February 12, 2024 (last updated February 16, 2024)
Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges.
Attacker Value
Unknown

CVE-2024-22229

Disclosure Date: January 24, 2024 (last updated February 06, 2024)
Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.
Attacker Value
Unknown

CVE-2021-25117

Disclosure Date: January 16, 2024 (last updated January 20, 2024)
The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.
Attacker Value
Unknown

CVE-2022-45809

Disclosure Date: December 19, 2023 (last updated December 23, 2023)
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0.
Attacker Value
Unknown

CVE-2021-27795

Disclosure Date: December 06, 2023 (last updated December 12, 2023)
Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a malicious party to forge a counterfeit license key that the Brocade Fabric OS platform would authenticate and activate as if it were a legitimate license key.
Attacker Value
Unknown

CVE-2023-37867

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8.
Attacker Value
Unknown

CVE-2023-4642

Disclosure Date: November 27, 2023 (last updated December 02, 2023)
The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.
Attacker Value
Unknown

CVE-2023-43082

Disclosure Date: November 22, 2023 (last updated November 30, 2023)
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.