Show filters
3,125 Total Results
Displaying 191-200 of 3,125
Sort by:
Attacker Value
Unknown

CVE-2024-4754

Disclosure Date: June 24, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.
0
Attacker Value
Unknown

CVE-2024-2003

Disclosure Date: June 21, 2024 (last updated February 26, 2025)
Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.
0
Attacker Value
Unknown

CVE-2024-34024

Disclosure Date: June 18, 2024 (last updated June 18, 2024)
Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine if a username is valid or not.
0
Attacker Value
Unknown

CVE-2024-33622

Disclosure Date: June 18, 2024 (last updated February 26, 2025)
Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, sensitive information may be obtained and/or the information stored in the database may be altered by a remote authenticated attacker.
0
Attacker Value
Unknown

CVE-2024-33620

Disclosure Date: June 18, 2024 (last updated February 26, 2025)
Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker.
0
Attacker Value
Unknown

CVE-2023-5527

Disclosure Date: June 18, 2024 (last updated February 26, 2025)
The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Attacker Value
Unknown

CVE-2023-51516

Disclosure Date: June 14, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.
Attacker Value
Unknown

CVE-2024-35249

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-35248

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-34684

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read or modify the remote server files.