Show filters
1,839 Total Results
Displaying 181-190 of 1,839
Sort by:
Attacker Value
Unknown

CVE-2024-37472

Disclosure Date: July 04, 2024 (last updated July 20, 2024)
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice allows Reflected XSS.This issue affects Woffice: from n/a through 5.4.8.
Attacker Value
Unknown

CVE-2024-37471

Disclosure Date: July 04, 2024 (last updated July 20, 2024)
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.
Attacker Value
Unknown

CVE-2023-7270

Disclosure Date: June 27, 2024 (last updated June 27, 2024)
An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible conhost.exe window running as the SYSTEM user when using the repair function of msiexec.exe. This allows a local, low-privileged attacker to use a chain of actions, to open a fully functional cmd.exe with the privileges of the SYSTEM user.
0
Attacker Value
Unknown

CVE-2024-5261

Disclosure Date: June 25, 2024 (last updated June 26, 2024)
Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice as a library to convert, view or otherwise interact with documents. LibreOffice internally makes use of "curl" to fetch remote resources such as images hosted on webservers. In affected versions of LibreOffice, when used in LibreOfficeKit mode only, then curl's TLS certification verification was disabled (CURLOPT_SSL_VERIFYPEER of false) In the fixed versions curl operates in LibreOfficeKit mode the same as in standard mode with CURLOPT_SSL_VERIFYPEER of true. This issue affects LibreOffice before version 24.2.4.
0
Attacker Value
Unknown

CVE-2024-4197

Disclosure Date: June 25, 2024 (last updated January 22, 2025)
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.
Attacker Value
Unknown

CVE-2024-6039

Disclosure Date: June 16, 2024 (last updated August 20, 2024)
A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of the argument dim leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268752.
Attacker Value
Unknown

CVE-2024-30101

Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Microsoft Office Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-34003

Disclosure Date: June 09, 2024 (last updated October 12, 2024)
Missing Authorization vulnerability in Woo WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.1.51.
Attacker Value
Unknown

CVE-2024-4706

Disclosure Date: May 23, 2024 (last updated January 05, 2025)
The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2024-3044

Disclosure Date: May 14, 2024 (last updated September 20, 2024)
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
0