Show filters
1,385 Total Results
Displaying 31-40 of 1,385
Sort by:
Attacker Value
Unknown

CVE-2024-37144

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Insecure Storage of Sensitive Information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. The attacker may be able to use information disclosed to gain unauthorized access to pods within the cluster.
0
Attacker Value
Unknown

CVE-2024-37143

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Improper Link Resolution Before File Access vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to execute arbitrary code on the system.
0
Attacker Value
Unknown

CVE-2024-53676

Disclosure Date: November 27, 2024 (last updated December 21, 2024)
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
Attacker Value
Unknown

CVE-2024-53675

Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
Attacker Value
Unknown

CVE-2024-53674

Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
Attacker Value
Unknown

CVE-2024-53673

Disclosure Date: November 26, 2024 (last updated December 18, 2024)
A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.
Attacker Value
Unknown

CVE-2024-11622

Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
Attacker Value
Unknown

CVE-2024-39726

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-47854

Disclosure Date: October 04, 2024 (last updated November 14, 2024)
An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.