Show filters
324 Total Results
Displaying 31-40 of 324
Sort by:
Attacker Value
Unknown
CVE-2023-1932
Disclosure Date: November 07, 2024 (last updated November 07, 2024)
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2024-5532
Disclosure Date: October 28, 2024 (last updated October 29, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.
The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system.
This issue affects Operations Agent: 12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26.
0
Attacker Value
Unknown
CVE-2024-6619
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.
0
Attacker Value
Unknown
CVE-2024-6618
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of a malicious dynamic-link library (DLL).
0
Attacker Value
Unknown
CVE-2021-22508
Disclosure Date: May 17, 2024 (last updated June 06, 2024)
A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application.
0
Attacker Value
Unknown
CVE-2024-28917
Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-0335
Disclosure Date: April 03, 2024 (last updated September 19, 2024)
ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may
be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst)
This issue affects Symphony Plus S+ Operations: from 3..0;0 through 3.3 SP1 RU4, from 2.1;0 through 2.1 SP2 RU3, from 2.0;0 through 2.0 SP6 TC6; Symphony Plus S+ Engineering: from 2.1 through 2.3 RU3; Symphony Plus S+ Analyst: from 7.0.0.0 through 7.2.0.2.
0
Attacker Value
Unknown
CVE-2024-21334
Disclosure Date: March 12, 2024 (last updated January 12, 2025)
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-21330
Disclosure Date: March 12, 2024 (last updated January 12, 2025)
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-22235
Disclosure Date: February 21, 2024 (last updated February 13, 2025)
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
0