Show filters
460 Total Results
Displaying 161-170 of 460
Sort by:
Attacker Value
Unknown

CVE-2024-21984

Disclosure Date: February 16, 2024 (last updated December 18, 2024)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult to exploit Reflected Cross-Site Scripting (XSS) vulnerability. Successful exploit requires the attacker to know specific information about the target instance and trick a privileged user into clicking a specially crafted link. This could allow the attacker to view or modify configuration settings or add or modify user accounts.
Attacker Value
Unknown

CVE-2024-21983

Disclosure Date: February 16, 2024 (last updated December 18, 2024)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to an out of memory condition or node reboot.
Attacker Value
Unknown

CVE-2023-27318

Disclosure Date: February 05, 2024 (last updated February 13, 2024)
StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to a crash of the Local Distribution Router (LDR) service.
Attacker Value
Unknown

CVE-2023-6645

Disclosure Date: January 11, 2024 (last updated January 18, 2024)
The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2022-36352

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.0.3.
Attacker Value
Unknown

CVE-2023-5384

Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Attacker Value
Unknown

CVE-2023-5236

Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
Attacker Value
Unknown

CVE-2023-3629

Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Attacker Value
Unknown

CVE-2023-3628

Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
Attacker Value
Unknown

CVE-2023-40211

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.