Show filters
591 Total Results
Displaying 141-150 of 591
Sort by:
Attacker Value
Unknown

CVE-2024-30119

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.
0
Attacker Value
Unknown

CVE-2024-35738

Disclosure Date: June 08, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kognetiks Kognetiks Chatbot for WordPress allows Stored XSS.This issue affects Kognetiks Chatbot for WordPress: from n/a through 1.9.8.
Attacker Value
Unknown

CVE-2023-43556

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Memory corruption in Hypervisor when platform information mentioned is not aligned.
Attacker Value
Unknown

CVE-2023-43551

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Attacker Value
Unknown

CVE-2023-43542

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
0
Attacker Value
Unknown

CVE-2023-43538

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Attacker Value
Unknown

CVE-2023-43537

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Information disclosure while handling T2LM Action Frame in WLAN Host.
Attacker Value
Unknown

CVE-2024-4344

Disclosure Date: June 02, 2024 (last updated June 02, 2024)
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.1.13. This is due to missing or incorrect nonce validation on the exec function. This makes it possible for unauthenticated attackers to disable pin protection for the admin interface of the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown

CVE-2024-4355

Disclosure Date: May 30, 2024 (last updated January 05, 2025)
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions up to, and including, 10.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose visitor data.
0
Attacker Value
Unknown

CVE-2024-36112

Disclosure Date: May 28, 2024 (last updated May 29, 2024)
Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`) and/or the members REST API view (`/api/extras/dynamic-groups/<uuid>/members/`) to list the objects that are members of a given Dynamic Group. In versions of Nautobot between 1.3.0 (where the Dynamic Groups feature was added) and 1.6.22 inclusive, and 2.0.0 through 2.2.4 inclusive, Nautobot fails to restrict these listings based on the member object permissions - for example a Dynamic Group of Device objects will list all Devices that it contains, regardless of the user's `dcim.view_device` permissions or lack thereof. This issue has been fixed in Nautobot versions 1.6.23 and 2.2.5. Users are advised to upgrade. This vulnerability can be partially mitigated by removing `extras.view_dynamicgroup` permission from users however a full fix will require…
0