Show filters
1,400 Total Results
Displaying 61-70 of 1,400
Sort by:
Attacker Value
Unknown

CVE-2024-9902

Disclosure Date: November 06, 2024 (last updated December 21, 2024)
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.
0
Attacker Value
Unknown

CVE-2024-50506

Disclosure Date: October 30, 2024 (last updated October 30, 2024)
Incorrect Privilege Assignment vulnerability in Azexo Marketing Automation by AZEXO allows Privilege Escalation.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.
0
Attacker Value
Unknown

CVE-2024-50480

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO allows Upload a Web Shell to a Web Server.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.
0
Attacker Value
Unknown

CVE-2024-47328

Disclosure Date: October 21, 2024 (last updated October 25, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Automation By Autonami allows SQL Injection.This issue affects Automation By Autonami: from n/a through 3.1.2.
Attacker Value
Unknown

CVE-2024-4692

Disclosure Date: October 16, 2024 (last updated October 22, 2024)
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate Service Virtualization server names. This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Attacker Value
Unknown

CVE-2024-4690

Disclosure Date: October 16, 2024 (last updated October 22, 2024)
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Attacker Value
Unknown

CVE-2024-4211

Disclosure Date: October 16, 2024 (last updated October 22, 2024)
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate ALM server names, usernames and client IDs configured to be used with ALM servers. This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Attacker Value
Unknown

CVE-2024-4189

Disclosure Date: October 16, 2024 (last updated October 22, 2024)
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Attacker Value
Unknown

CVE-2024-4184

Disclosure Date: October 16, 2024 (last updated October 22, 2024)
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Attacker Value
Unknown

CVE-2024-10033

Disclosure Date: October 16, 2024 (last updated October 31, 2024)
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.