Show filters
591 Total Results
Displaying 141-150 of 591
Sort by:
Attacker Value
Unknown
CVE-2024-30119
Disclosure Date: June 14, 2024 (last updated June 15, 2024)
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection.
0
Attacker Value
Unknown
CVE-2024-35738
Disclosure Date: June 08, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kognetiks Kognetiks Chatbot for WordPress allows Stored XSS.This issue affects Kognetiks Chatbot for WordPress: from n/a through 1.9.8.
0
Attacker Value
Unknown
CVE-2023-43556
Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Memory corruption in Hypervisor when platform information mentioned is not aligned.
0
Attacker Value
Unknown
CVE-2023-43551
Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
0
Attacker Value
Unknown
CVE-2023-43542
Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
0
Attacker Value
Unknown
CVE-2023-43538
Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
0
Attacker Value
Unknown
CVE-2023-43537
Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Information disclosure while handling T2LM Action Frame in WLAN Host.
0
Attacker Value
Unknown
CVE-2024-4344
Disclosure Date: June 02, 2024 (last updated June 02, 2024)
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.1.13. This is due to missing or incorrect nonce validation on the exec function. This makes it possible for unauthenticated attackers to disable pin protection for the admin interface of the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-4355
Disclosure Date: May 30, 2024 (last updated January 05, 2025)
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions up to, and including, 10.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose visitor data.
0
Attacker Value
Unknown
CVE-2024-36112
Disclosure Date: May 28, 2024 (last updated May 29, 2024)
Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`) and/or the members REST API view (`/api/extras/dynamic-groups/<uuid>/members/`) to list the objects that are members of a given Dynamic Group. In versions of Nautobot between 1.3.0 (where the Dynamic Groups feature was added) and 1.6.22 inclusive, and 2.0.0 through 2.2.4 inclusive, Nautobot fails to restrict these listings based on the member object permissions - for example a Dynamic Group of Device objects will list all Devices that it contains, regardless of the user's `dcim.view_device` permissions or lack thereof. This issue has been fixed in Nautobot versions 1.6.23 and 2.2.5. Users are advised to upgrade. This vulnerability can be partially mitigated by removing `extras.view_dynamicgroup` permission from users however a full fix will require…
0