Show filters
292 Total Results
Displaying 51-60 of 292
Sort by:
Attacker Value
Unknown
CVE-2023-41933
Disclosure Date: September 06, 2023 (last updated February 25, 2025)
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2023-41932
Disclosure Date: September 06, 2023 (last updated February 25, 2025)
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.
0
Attacker Value
Unknown
CVE-2023-41931
Disclosure Date: September 06, 2023 (last updated February 25, 2025)
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not property sanitize or escape the timestamp value from history entries when rendering a history entry on the history view, resulting in a stored cross-site scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2023-41930
Disclosure Date: September 06, 2023 (last updated February 25, 2025)
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.
0
Attacker Value
Unknown
CVE-2023-29505
Disclosure Date: August 04, 2023 (last updated February 25, 2025)
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
0
Attacker Value
Unknown
CVE-2023-23842
Disclosure Date: July 26, 2023 (last updated February 25, 2025)
The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2023-22440
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2022-43465
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access.
0
Attacker Value
Unknown
CVE-2022-41610
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.
0
Attacker Value
Unknown
CVE-2023-28444
Disclosure Date: March 24, 2023 (last updated February 24, 2025)
angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables. angular-server-side-configuration detects used environment variables in TypeScript (.ts) files during build time of an Angular CLI project. The detected environment variables are written to a ngssc.json file in the output directory.
During deployment of an Angular based app, the environment variables based on the variables from ngssc.json are inserted into the apps index.html (or defined index file). With version 15.0.0 the environment variable detection was widened to the entire project, relative to the angular.json file from the Angular CLI. In a monorepo setup, this could lead to environment variables intended for a backend/service to be detected and written to the ngssc.json, which would then be populated and exposed via index.html. This has NO IMPACT, in a plain Angular project that has no backend component. This vulnerability has b…
0