Show filters
1,839 Total Results
Displaying 181-190 of 1,839
Sort by:
Attacker Value
Unknown
CVE-2024-37472
Disclosure Date: July 04, 2024 (last updated July 20, 2024)
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice allows Reflected XSS.This issue affects Woffice: from n/a through 5.4.8.
0
Attacker Value
Unknown
CVE-2024-37471
Disclosure Date: July 04, 2024 (last updated July 20, 2024)
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.
0
Attacker Value
Unknown
CVE-2023-7270
Disclosure Date: June 27, 2024 (last updated June 27, 2024)
An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed.
The SoftMaker Office and FreeOffice MSI installer files were found to
produce a visible conhost.exe window running as the SYSTEM user when
using the repair function of msiexec.exe. This allows a local,
low-privileged attacker to use a chain of actions, to open a fully
functional cmd.exe with the privileges of the SYSTEM user.
0
Attacker Value
Unknown
CVE-2024-5261
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification
LibreOfficeKit can be used for accessing LibreOffice functionality
through C/C++. Typically this is used by third party components to reuse
LibreOffice as a library to convert, view or otherwise interact with
documents.
LibreOffice internally makes use of "curl" to fetch remote resources such as images hosted on webservers.
In
affected versions of LibreOffice, when used in LibreOfficeKit mode
only, then curl's TLS certification verification was disabled
(CURLOPT_SSL_VERIFYPEER of false)
In the fixed versions curl operates in LibreOfficeKit mode the same as in standard mode with CURLOPT_SSL_VERIFYPEER of true.
This issue affects LibreOffice before version 24.2.4.
0
Attacker Value
Unknown
CVE-2024-4197
Disclosure Date: June 25, 2024 (last updated January 22, 2025)
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.
0
Attacker Value
Unknown
CVE-2024-6039
Disclosure Date: June 16, 2024 (last updated August 20, 2024)
A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of the argument dim leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268752.
0
Attacker Value
Unknown
CVE-2024-30101
Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Microsoft Office Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-34003
Disclosure Date: June 09, 2024 (last updated October 12, 2024)
Missing Authorization vulnerability in Woo WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.1.51.
0
Attacker Value
Unknown
CVE-2024-4706
Disclosure Date: May 23, 2024 (last updated January 05, 2025)
The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-3044
Disclosure Date: May 14, 2024 (last updated September 20, 2024)
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
0