Show filters
1,839 Total Results
Displaying 131-140 of 1,839
Sort by:
Attacker Value
Unknown
CVE-2024-43609
Disclosure Date: October 08, 2024 (last updated October 18, 2024)
Microsoft Office Spoofing Vulnerability
0
Attacker Value
Unknown
CVE-2024-43505
Disclosure Date: October 08, 2024 (last updated October 18, 2024)
Microsoft Office Visio Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-43504
Disclosure Date: October 08, 2024 (last updated October 22, 2024)
Microsoft Excel Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-45278
Disclosure Date: October 08, 2024 (last updated November 15, 2024)
SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2024-47657
Disclosure Date: October 04, 2024 (last updated October 17, 2024)
This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.
0
Attacker Value
Unknown
CVE-2024-9328
Disclosure Date: September 29, 2024 (last updated October 01, 2024)
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /control/edit_client.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-9318
Disclosure Date: September 28, 2024 (last updated October 02, 2024)
A vulnerability, which was classified as critical, has been found in SourceCodester Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/activate.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-9296
Disclosure Date: September 28, 2024 (last updated October 01, 2024)
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /control/forgot_pass.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-9295
Disclosure Date: September 28, 2024 (last updated October 01, 2024)
A vulnerability was found in SourceCodester Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /control/login.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-47222
Disclosure Date: September 23, 2024 (last updated October 01, 2024)
New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.
0