Show filters
2,048 Total Results
Displaying 31-40 of 2,048
Sort by:
Attacker Value
Unknown

CVE-2024-35145

Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2024-35144

Disclosure Date: January 25, 2025 (last updated January 26, 2025)
IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.
Attacker Value
Unknown

CVE-2024-55930

Disclosure Date: January 23, 2025 (last updated February 25, 2025)
Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files
0
Attacker Value
Unknown

CVE-2024-55929

Disclosure Date: January 23, 2025 (last updated February 25, 2025)
A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as though messages are sent from trusted sources.
0
Attacker Value
Unknown

CVE-2024-55928

Disclosure Date: January 23, 2025 (last updated February 25, 2025)
Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows attackers to intercept or access secrets without encryption
0
Attacker Value
Unknown

CVE-2024-55927

Disclosure Date: January 23, 2025 (last updated February 25, 2025)
A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading to unauthorized access to sensitive functions.
0
Attacker Value
Unknown

CVE-2024-55926

Disclosure Date: January 23, 2025 (last updated February 25, 2025)
A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data
0
Attacker Value
Unknown

CVE-2024-55925

Disclosure Date: January 23, 2025 (last updated February 25, 2025)
In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This exploit targets improper host validation, potentially exposing sensitive API endpoints.
0
Attacker Value
Unknown

CVE-2024-13026

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft valid authentication tokens and access the component. Other components of navify® Algorithm Suite are not affected.
0
Attacker Value
Unknown

CVE-2024-12454

Disclosure Date: December 18, 2024 (last updated December 18, 2024)
The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.23. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.