Show filters
3,126 Total Results
Displaying 281-290 of 3,126
Sort by:
Attacker Value
Unknown
CVE-2024-21380
Disclosure Date: February 13, 2024 (last updated February 26, 2025)
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
0
Attacker Value
Unknown
CVE-2024-20695
Disclosure Date: February 13, 2024 (last updated February 26, 2025)
Skype for Business Information Disclosure Vulnerability
0
Attacker Value
Unknown
CVE-2024-20673
Disclosure Date: February 13, 2024 (last updated February 26, 2025)
Microsoft Office Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-22128
Disclosure Date: February 13, 2024 (last updated February 26, 2025)
SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.
0
Attacker Value
Unknown
CVE-2023-6499
Disclosure Date: February 12, 2024 (last updated February 26, 2025)
The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
0
Attacker Value
Unknown
CVE-2024-0971
Disclosure Date: February 07, 2024 (last updated February 26, 2025)
A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.
0
Attacker Value
Unknown
CVE-2024-0955
Disclosure Date: February 07, 2024 (last updated February 26, 2025)
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.
0
Attacker Value
Unknown
CVE-2023-50947
Disclosure Date: February 04, 2024 (last updated February 26, 2025)
IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 275665.
0
Attacker Value
Unknown
CVE-2024-0933
Disclosure Date: January 26, 2024 (last updated February 26, 2025)
A vulnerability was found in Niushop B2B2C V5 and classified as critical. Affected by this issue is some unknown functionality of the file \app\model\Upload.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252140. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-20904
Disclosure Date: January 16, 2024 (last updated January 21, 2024)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).
0