Show filters
1,540 Total Results
Displaying 31-40 of 1,540
Sort by:
Attacker Value
Unknown
CVE-2024-11401
Disclosure Date: December 11, 2024 (last updated December 21, 2024)
Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorization checks, an attacker can successfully update the password policy in the platform settings as a standard user by crafting an API (the functionality was not possible through the platform's User Interface). This vulnerability has been fixed as of November 13th 2024.
0
Attacker Value
Unknown
CVE-2024-37144
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Insecure Storage of Sensitive Information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. The attacker may be able to use information disclosed to gain unauthorized access to pods within the cluster.
0
Attacker Value
Unknown
CVE-2024-37143
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Improper Link Resolution Before File Access vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to execute arbitrary code on the system.
0
Attacker Value
Unknown
CVE-2024-53676
Disclosure Date: November 27, 2024 (last updated December 21, 2024)
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
0
Attacker Value
Unknown
CVE-2024-53675
Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
0
Attacker Value
Unknown
CVE-2024-53674
Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
0
Attacker Value
Unknown
CVE-2024-53673
Disclosure Date: November 26, 2024 (last updated December 18, 2024)
A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.
0
Attacker Value
Unknown
CVE-2024-11622
Disclosure Date: November 26, 2024 (last updated December 18, 2024)
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
0
Attacker Value
Unknown
CVE-2024-10390
Disclosure Date: November 18, 2024 (last updated November 19, 2024)
The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePreferences' function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-39726
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
0