Show filters
4,200 Total Results
Displaying 151-160 of 4,200
Sort by:
Attacker Value
Unknown

CVE-2024-52520

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.
0
Attacker Value
Unknown

CVE-2024-52515

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provider, a malicious user could upload a manipulated SVG file referencing paths. If the file would exist the preview of the SVG would preview the other file instead. It is recommended that the Nextcloud Server is upgraded to 27.1.10, 28.0.6 or 29.0.1 and Nextcloud Enterprise Server is upgraded to 24.0.12.15, 25.0.13.10, 26.0.13.4, 27.1.10, 28.0.6 or 29.0.1.
0
Attacker Value
Unknown

CVE-2024-10534

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection.This issue affects Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS): before 2024.
Attacker Value
Unknown

CVE-2024-10924

Disclosure Date: November 15, 2024 (last updated November 21, 2024)
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).
Attacker Value
Unknown

CVE-2024-45642

Disclosure Date: November 14, 2024 (last updated November 16, 2024)
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2024-45099

Disclosure Date: November 14, 2024 (last updated November 16, 2024)
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2024-52549

Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
0
Attacker Value
Unknown

CVE-2024-24914

Disclosure Date: November 07, 2024 (last updated November 08, 2024)
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.
0
Attacker Value
Unknown

CVE-2024-7059

Disclosure Date: November 05, 2024 (last updated November 09, 2024)
A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.
0
Attacker Value
Unknown

CVE-2024-38777

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in CreativeMotion Titan Anti-spam & Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Titan Anti-spam & Security: from n/a through 7.3.6.
0