Show filters
13,157 Total Results
Displaying 531-540 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-34696

Disclosure Date: July 01, 2024 (last updated July 04, 2024)
GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and 2.25.1, GeoServer's Server Status page and REST API lists all environment variables and Java properties to any GeoServer user with administrative rights as part of those modules' status message. These variables/properties can also contain sensitive information, such as database passwords or API keys/tokens. Additionally, many community-developed GeoServer container images `export` other credentials from their start-up scripts as environment variables to the GeoServer (`java`) process. The precise scope of the issue depends on which container image is used and how it is configured. The `about status` API endpoint which powers the Server Status page is only available to administrators.Depending on the operating environment, administrators might have legitimate access to credentials in other ways, but this issue defeats more sophisticated co…
Attacker Value
Unknown

CVE-2024-39428

Disclosure Date: July 01, 2024 (last updated August 28, 2024)
In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Attacker Value
Unknown

CVE-2024-39427

Disclosure Date: July 01, 2024 (last updated August 28, 2024)
In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Attacker Value
Unknown

CVE-2024-3123

Disclosure Date: July 01, 2024 (last updated July 01, 2024)
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
Attacker Value
Unknown

CVE-2024-3122

Disclosure Date: July 01, 2024 (last updated July 01, 2024)
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
Attacker Value
Unknown

CVE-2024-35260

Disclosure Date: June 27, 2024 (last updated June 28, 2024)
An authenticated attacker can exploit an Untrusted Search Path vulnerability in Microsoft Dataverse to execute code over a network.
Attacker Value
Unknown

CVE-2024-35153

Disclosure Date: June 27, 2024 (last updated August 03, 2024)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 292640.
Attacker Value
Unknown

CVE-2024-39373

Disclosure Date: June 27, 2024 (last updated September 18, 2024)
TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges.
Attacker Value
Unknown

CVE-2024-4664

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
Attacker Value
Unknown

CVE-2024-5430

Disclosure Date: June 27, 2024 (last updated June 29, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.