Show filters
591 Total Results
Displaying 181-190 of 591
Sort by:
Attacker Value
Unknown
CVE-2023-28547
Disclosure Date: April 01, 2024 (last updated February 26, 2025)
Memory corruption in SPS Application while requesting for public key in sorter TA.
0
Attacker Value
Unknown
CVE-2024-0259
Disclosure Date: March 28, 2024 (last updated February 26, 2025)
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.
0
Attacker Value
Unknown
CVE-2024-29100
Disclosure Date: March 28, 2024 (last updated February 26, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
0
Attacker Value
Unknown
CVE-2024-29090
Disclosure Date: March 28, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
0
Attacker Value
Unknown
CVE-2024-29199
Disclosure Date: March 26, 2024 (last updated February 26, 2025)
Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to unauthenticated (anonymous) users. These endpoints will not disclose any Nautobot data to an unauthenticated user unless the Nautobot configuration variable EXEMPT_VIEW_PERMISSIONS is changed from its default value (an empty list) to permit access to specific data by unauthenticated users. This vulnerability is fixed in 1.6.16 and 2.1.9.
0
Attacker Value
Unknown
CVE-2020-36826
Disclosure Date: March 25, 2024 (last updated February 26, 2025)
A vulnerability was found in AwesomestCode LiveBot. It has been classified as problematic. Affected is the function parseSend of the file js/parseMessage.js. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. Upgrading to version 0.1 is able to address this issue. The name of the patch is 57505527f838d1e46e8f93d567ba552a30185bfa. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-257784.
0
Attacker Value
Unknown
CVE-2024-0449
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2024-0447
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the artibot_update function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to update plugin settings.
0
Attacker Value
Unknown
CVE-2024-2413
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and timestamp to generate an authentication code. With this authentication code, they can obtain administrator privileges and subsequently execute arbitrary code on the remote server using built-in system functionality.
0
Attacker Value
Unknown
CVE-2023-43552
Disclosure Date: March 04, 2024 (last updated February 26, 2025)
Memory corruption while processing MBSSID beacon containing several subelement IE.
0