Show filters
1,839 Total Results
Displaying 151-160 of 1,839
Sort by:
Attacker Value
Unknown

CVE-2024-38250

Disclosure Date: September 10, 2024 (last updated September 18, 2024)
Windows Graphics Component Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-38226

Disclosure Date: September 10, 2024 (last updated September 12, 2024)
Microsoft Publisher Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2024-8601

Disclosure Date: September 09, 2024 (last updated September 18, 2024)
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to unauthorized access to sensitive information belonging to other users.
Attacker Value
Unknown

CVE-2024-8367

Disclosure Date: September 01, 2024 (last updated September 01, 2024)
A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a6cd31. It has been classified as problematic. Affected is an unknown function of the file src/main/java/uk/gov/hmcts/probate/service/NotificationService.java of the component Markdown Handler. The manipulation leads to injection. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The patch is identified as d90230d7cf575e5b0852d56660104c8bd2503c34. It is recommended to apply a patch to fix this issue.
0
Attacker Value
Unknown

CVE-2024-7263

Disclosure Date: August 15, 2024 (last updated August 22, 2024)
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.1.0.17119 to mitigate CVE-2024-7262 was not restrictive enough. Another parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.
Attacker Value
Unknown

CVE-2024-7262

Disclosure Date: August 15, 2024 (last updated August 22, 2024)
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document
Attacker Value
Unknown

CVE-2024-38189

Disclosure Date: August 13, 2024 (last updated August 17, 2024)
Microsoft Project Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-38173

Disclosure Date: August 13, 2024 (last updated August 17, 2024)
Microsoft Outlook Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-38172

Disclosure Date: August 13, 2024 (last updated August 17, 2024)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-38171

Disclosure Date: August 13, 2024 (last updated August 17, 2024)
Microsoft PowerPoint Remote Code Execution Vulnerability