Show filters
461 Total Results
Displaying 21-30 of 461
Sort by:
Attacker Value
Unknown

CVE-2024-50404

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later
0
Attacker Value
Unknown

CVE-2024-53770

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Peter MacIntyre RingCentral Communications allows Stored XSS.This issue affects RingCentral Communications: from n/a through 1.6.1.
0
Attacker Value
Unknown

CVE-2024-11025

Disclosure Date: November 27, 2024 (last updated December 21, 2024)
An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administration panel to gain read and write access to a specific log file of the device.
Attacker Value
Unknown

CVE-2024-11209

Disclosure Date: November 14, 2024 (last updated November 20, 2024)
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-11208

Disclosure Date: November 14, 2024 (last updated November 20, 2024)
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-10203

Disclosure Date: November 07, 2024 (last updated November 07, 2024)
Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.
0
Attacker Value
Unknown

CVE-2024-47487

Disclosure Date: October 18, 2024 (last updated October 23, 2024)
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.
Attacker Value
Unknown

CVE-2024-47486

Disclosure Date: October 18, 2024 (last updated October 23, 2024)
There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.
Attacker Value
Unknown

CVE-2024-47485

Disclosure Date: October 18, 2024 (last updated October 23, 2024)
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
Attacker Value
Unknown

CVE-2024-20280

Disclosure Date: October 16, 2024 (last updated October 17, 2024)
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server certificate and key.
0