Show filters
106 topics marked with the following tags:
Displaying 51-60 of 106
Sort by:
Attacker Value
Low
CVE-2020-8500
Disclosure Date: March 02, 2020 (last updated November 08, 2023)
In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality
0
Attacker Value
Moderate
CVE-2021-26431
Disclosure Date: August 12, 2021 (last updated December 29, 2023)
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
1
Attacker Value
Moderate
CVE-2023-33140
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
Microsoft OneNote Spoofing Vulnerability
2
Attacker Value
Moderate
CVE-2024-30055
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1
Attacker Value
High
CVE-2023-33131
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
Microsoft Outlook Remote Code Execution Vulnerability
2
Attacker Value
Moderate
CVE-2020-0668
Disclosure Date: February 11, 2020 (last updated October 06, 2023)
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0669, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672.
1
Attacker Value
Moderate
CVE-2020-3580
Disclosure Date: October 21, 2020 (last updated August 15, 2024)
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
3
Attacker Value
High
CVE-2019-19452
Disclosure Date: February 21, 2020 (last updated October 06, 2023)
A buffer overflow was found in Patriot Viper RGB through 1.1 when processing IoControlCode 0x80102040. Local attackers (including low integrity processes) can exploit this to gain NT AUTHORITY\SYSTEM privileges.
0
Attacker Value
Low
CVE-2024-1548
Disclosure Date: February 20, 2024 (last updated February 21, 2024)
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
2
Attacker Value
Moderate
CVE-2023-6933
Disclosure Date: February 05, 2024 (last updated February 15, 2024)
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
2