Show filters
13,154 Total Results
Displaying 381-390 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-6661

Disclosure Date: July 27, 2024 (last updated July 28, 2024)
The ParityPress – Parity Pricing with Discount Rules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Discount Text' in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Attacker Value
Unknown

CVE-2024-38512

Disclosure Date: July 26, 2024 (last updated July 28, 2024)
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
Attacker Value
Unknown

CVE-2024-38511

Disclosure Date: July 26, 2024 (last updated July 28, 2024)
A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
Attacker Value
Unknown

CVE-2024-38510

Disclosure Date: July 26, 2024 (last updated July 28, 2024)
A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
Attacker Value
Unknown

CVE-2024-38509

Disclosure Date: July 26, 2024 (last updated July 28, 2024)
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to execute arbitrary code via a specially crafted IPMI command.
Attacker Value
Unknown

CVE-2024-38288

Disclosure Date: July 25, 2024 (last updated August 14, 2024)
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.
Attacker Value
Unknown

CVE-2024-40318

Disclosure Date: July 25, 2024 (last updated August 27, 2024)
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
Attacker Value
Unknown

CVE-2024-40873

Disclosure Date: July 25, 2024 (last updated August 03, 2024)
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions can interfere with another system administrator’s use of the publishing UI when the administrators are editing the same management object. The scope is unchanged, there is no loss of confidentiality. Impact to system availability is none, impact to system integrity is high.
Attacker Value
Unknown

CVE-2024-5067

Disclosure Date: July 24, 2024 (last updated September 06, 2024)
An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.
Attacker Value
Unknown

CVE-2024-0231

Disclosure Date: July 24, 2024 (last updated September 12, 2024)
A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.