Show filters
1,197 Total Results
Displaying 131-140 of 1,197
Sort by:
Attacker Value
Unknown

CVE-2024-34105

Disclosure Date: June 13, 2024 (last updated July 10, 2024)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Attacker Value
Unknown

CVE-2024-34104

Disclosure Date: June 13, 2024 (last updated July 10, 2024)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2024-34103

Disclosure Date: June 13, 2024 (last updated July 10, 2024)
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the application. Exploitation of this issue does not require user interaction, but attack complexity is high.
Attacker Value
Unknown

CVE-2024-5909

Disclosure Date: June 12, 2024 (last updated August 08, 2024)
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Attacker Value
Unknown

CVE-2024-5907

Disclosure Date: June 12, 2024 (last updated August 08, 2024)
A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.
Attacker Value
Unknown

CVE-2024-5905

Disclosure Date: June 12, 2024 (last updated August 08, 2024)
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.
Attacker Value
Unknown

CVE-2024-35254

Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Azure Monitor Agent Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-36358

Disclosure Date: June 10, 2024 (last updated June 11, 2024)
A link following vulnerability in Trend Micro Deep Security 20.x agents below build 20.0.1-3180 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2024-29853

Disclosure Date: May 22, 2024 (last updated May 23, 2024)
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.
0
Attacker Value
Unknown

CVE-2024-3292

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292
0