Show filters
3,125 Total Results
Displaying 191-200 of 3,125
Sort by:
Attacker Value
Unknown
CVE-2024-4754
Disclosure Date: June 24, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.
0
Attacker Value
Unknown
CVE-2024-2003
Disclosure Date: June 21, 2024 (last updated February 26, 2025)
Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.
0
Attacker Value
Unknown
CVE-2024-34024
Disclosure Date: June 18, 2024 (last updated June 18, 2024)
Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine if a username is valid or not.
0
Attacker Value
Unknown
CVE-2024-33622
Disclosure Date: June 18, 2024 (last updated February 26, 2025)
Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, sensitive information may be obtained and/or the information stored in the database may be altered by a remote authenticated attacker.
0
Attacker Value
Unknown
CVE-2024-33620
Disclosure Date: June 18, 2024 (last updated February 26, 2025)
Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker.
0
Attacker Value
Unknown
CVE-2023-5527
Disclosure Date: June 18, 2024 (last updated February 26, 2025)
The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
0
Attacker Value
Unknown
CVE-2023-51516
Disclosure Date: June 14, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.
0
Attacker Value
Unknown
CVE-2024-35249
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-35248
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-34684
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
On Unix, SAP BusinessObjects Business
Intelligence Platform (Scheduling) allows an authenticated attacker with
administrator access on the local server to access the password of a local
account. As a result, an attacker can obtain non-administrative user
credentials, which will allow them to read or modify the remote server files.
0