Show filters
3,126 Total Results
Displaying 281-290 of 3,126
Sort by:
Attacker Value
Unknown

CVE-2024-21380

Disclosure Date: February 13, 2024 (last updated February 26, 2025)
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
Attacker Value
Unknown

CVE-2024-20695

Disclosure Date: February 13, 2024 (last updated February 26, 2025)
Skype for Business Information Disclosure Vulnerability
Attacker Value
Unknown

CVE-2024-20673

Disclosure Date: February 13, 2024 (last updated February 26, 2025)
Microsoft Office Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-22128

Disclosure Date: February 13, 2024 (last updated February 26, 2025)
SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.
Attacker Value
Unknown

CVE-2023-6499

Disclosure Date: February 12, 2024 (last updated February 26, 2025)
The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Attacker Value
Unknown

CVE-2024-0971

Disclosure Date: February 07, 2024 (last updated February 26, 2025)
A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.
Attacker Value
Unknown

CVE-2024-0955

Disclosure Date: February 07, 2024 (last updated February 26, 2025)
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.
Attacker Value
Unknown

CVE-2023-50947

Disclosure Date: February 04, 2024 (last updated February 26, 2025)
IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 275665.
Attacker Value
Unknown

CVE-2024-0933

Disclosure Date: January 26, 2024 (last updated February 26, 2025)
A vulnerability was found in Niushop B2B2C V5 and classified as critical. Affected by this issue is some unknown functionality of the file \app\model\Upload.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252140. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-20904

Disclosure Date: January 16, 2024 (last updated January 21, 2024)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).