Show filters
71,351 Total Results
Displaying 431-440 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2024-7029
Disclosure Date: August 02, 2024 (last updated September 18, 2024)
Commands can be injected over the network and executed without authentication.
1
Attacker Value
Moderate
CVE-2024-5910
Disclosure Date: July 10, 2024 (last updated November 09, 2024)
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.
Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
1
Attacker Value
Very High
CVE-2024-4879
Disclosure Date: July 10, 2024 (last updated December 21, 2024)
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
1
Attacker Value
Unknown
CVE-2024-38077
Disclosure Date: July 09, 2024 (last updated January 12, 2025)
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
2
Attacker Value
Very Low
CVE-2024-6100
Disclosure Date: June 20, 2024 (last updated June 21, 2024)
Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
1
Attacker Value
Low
CVE-2024-23692
Disclosure Date: May 31, 2024 (last updated July 11, 2024)
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
1
Attacker Value
Moderate
CVE-2024-30055
Disclosure Date: May 14, 2024 (last updated January 05, 2025)
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1
Attacker Value
Unknown
CVE-2024-26026
Disclosure Date: May 08, 2024 (last updated December 21, 2024)
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
2
Attacker Value
Unknown
CVE-2024-1283
Disclosure Date: February 07, 2024 (last updated February 15, 2024)
Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
2
Attacker Value
Unknown
CVE-2024-23222
Disclosure Date: January 23, 2024 (last updated June 11, 2024)
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
2