Show filters
310 Total Results
Displaying 21-30 of 310
Sort by:
Attacker Value
Unknown
CVE-2024-45841
Disclosure Date: December 05, 2024 (last updated February 27, 2025)
Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific file, the information containing credentials may be obtained.
0
Attacker Value
Unknown
CVE-2024-5890
Disclosure Date: December 02, 2024 (last updated February 27, 2025)
ServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability could potentially enable an unauthenticated user to modify a web page or redirect users to another website.
ServiceNow released updates to customers that addressed this vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance(s) as soon as possible.
0
Attacker Value
Unknown
CVE-2024-52503
Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tailored Web Services Tailored Tools allows Stored XSS.This issue affects Tailored Tools: from n/a through 1.8.4.
0
Attacker Value
Unknown
CVE-2024-52959
Disclosure Date: November 27, 2024 (last updated February 27, 2025)
A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.
0
Attacker Value
Unknown
CVE-2024-52958
Disclosure Date: November 27, 2024 (last updated February 27, 2025)
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.
0
Attacker Value
Unknown
CVE-2024-51633
Disclosure Date: November 19, 2024 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in IvyCat Web Services Simple Page Specific Sidebars allows Stored XSS.This issue affects Simple Page Specific Sidebars: from n/a through 2.14.1.
0
Attacker Value
Unknown
CVE-2024-50549
Disclosure Date: November 19, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bonway Services Bonway Static Block Editor allows DOM-Based XSS.This issue affects Bonway Static Block Editor: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-11021
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser.
0
Attacker Value
Unknown
CVE-2024-11020
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
0
Attacker Value
Unknown
CVE-2024-11019
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.
0