Show filters
360 Total Results
Displaying 41-50 of 360
Sort by:
Attacker Value
Unknown

CVE-2023-5764

Disclosure Date: December 12, 2023 (last updated April 25, 2024)
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Attacker Value
Unknown

CVE-2023-27418

Disclosure Date: November 12, 2023 (last updated November 18, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite – add sticky fixed buttons plugin <= 4.0 versions.
Attacker Value
Unknown

CVE-2023-26300

Disclosure Date: October 18, 2023 (last updated November 01, 2023)
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.
Attacker Value
Unknown

CVE-2023-22127

Disclosure Date: October 17, 2023 (last updated October 24, 2023)
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Content Access SDK, Image Export SDK, PDF Export SDK, HTML Export SDK). The supported version that is affected is 8.5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Attacker Value
Unknown

CVE-2023-4380

Disclosure Date: October 04, 2023 (last updated April 25, 2024)
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
Attacker Value
Unknown

CVE-2023-3971

Disclosure Date: October 04, 2023 (last updated April 25, 2024)
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
Attacker Value
Unknown

CVE-2023-26141

Disclosure Date: September 14, 2023 (last updated October 31, 2023)
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.
Attacker Value
Unknown

CVE-2023-4828

Disclosure Date: September 13, 2023 (last updated October 13, 2023)
An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the server's configuration of any already-registered agent so that the agent sends all future communications to an attacker-chosen URL. This could result in disclosure of sensitive data events from the agent about the personally identifiable information (PII) and intellectual property it monitors, and all such data could be altered or deleted before reaching the ITM Server. An attacker must first successfully obtain valid agent credentials and agent hostname. All versions prior to 7.14.3.69 are affected.
Attacker Value
Unknown

CVE-2023-4803

Disclosure Date: September 13, 2023 (last updated October 08, 2023)
A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.
Attacker Value
Unknown

CVE-2023-4802

Disclosure Date: September 13, 2023 (last updated October 08, 2023)
A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.