Show filters
460 Total Results
Displaying 161-170 of 460
Sort by:
Attacker Value
Unknown
CVE-2024-21984
Disclosure Date: February 16, 2024 (last updated December 18, 2024)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8
are susceptible to a difficult to exploit Reflected Cross-Site Scripting
(XSS) vulnerability. Successful exploit requires the attacker to know
specific information about the target instance and trick a privileged
user into clicking a specially crafted link. This could allow the
attacker to view or modify configuration settings or add or modify user
accounts.
0
Attacker Value
Unknown
CVE-2024-21983
Disclosure Date: February 16, 2024 (last updated December 18, 2024)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8
are susceptible to a Denial of Service (DoS) vulnerability. Successful
exploit by an authenticated attacker could lead to an out of memory
condition or node reboot.
0
Attacker Value
Unknown
CVE-2023-27318
Disclosure Date: February 05, 2024 (last updated February 13, 2024)
StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through
11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A
successful exploit could lead to a crash of the Local Distribution
Router (LDR) service.
0
Attacker Value
Unknown
CVE-2023-6645
Disclosure Date: January 11, 2024 (last updated January 18, 2024)
The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-36352
Disclosure Date: January 08, 2024 (last updated January 12, 2024)
Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.0.3.
0
Attacker Value
Unknown
CVE-2023-5384
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
0
Attacker Value
Unknown
CVE-2023-5236
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
0
Attacker Value
Unknown
CVE-2023-3629
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
0
Attacker Value
Unknown
CVE-2023-3628
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
0
Attacker Value
Unknown
CVE-2023-40211
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.
0