Show filters
360 Total Results
Displaying 41-50 of 360
Sort by:
Attacker Value
Unknown
CVE-2023-5764
Disclosure Date: December 12, 2023 (last updated April 25, 2024)
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
0
Attacker Value
Unknown
CVE-2023-27418
Disclosure Date: November 12, 2023 (last updated November 18, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite – add sticky fixed buttons plugin <= 4.0 versions.
0
Attacker Value
Unknown
CVE-2023-26300
Disclosure Date: October 18, 2023 (last updated November 01, 2023)
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.
0
Attacker Value
Unknown
CVE-2023-22127
Disclosure Date: October 17, 2023 (last updated October 24, 2023)
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Content Access SDK, Image Export SDK, PDF Export SDK, HTML Export SDK). The supported version that is affected is 8.5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
0
Attacker Value
Unknown
CVE-2023-4380
Disclosure Date: October 04, 2023 (last updated April 25, 2024)
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
0
Attacker Value
Unknown
CVE-2023-3971
Disclosure Date: October 04, 2023 (last updated April 25, 2024)
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
0
Attacker Value
Unknown
CVE-2023-26141
Disclosure Date: September 14, 2023 (last updated October 31, 2023)
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.
0
Attacker Value
Unknown
CVE-2023-4828
Disclosure Date: September 13, 2023 (last updated October 13, 2023)
An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the server's configuration of any already-registered agent so that the agent sends all future communications to an attacker-chosen URL. This could result in disclosure of sensitive data events from the agent about the personally identifiable information (PII) and intellectual property it monitors, and all such data could be altered or deleted before reaching the ITM Server. An attacker must first successfully obtain valid agent credentials and agent hostname. All versions prior to 7.14.3.69 are affected.
0
Attacker Value
Unknown
CVE-2023-4803
Disclosure Date: September 13, 2023 (last updated October 08, 2023)
A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.
0
Attacker Value
Unknown
CVE-2023-4802
Disclosure Date: September 13, 2023 (last updated October 08, 2023)
A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected.
0