Show filters
1,540 Total Results
Displaying 61-70 of 1,540
Sort by:
Attacker Value
Unknown

CVE-2024-21131

Disclosure Date: July 16, 2024 (last updated December 21, 2024)
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed…
Attacker Value
Unknown

CVE-2024-5810

Disclosure Date: July 09, 2024 (last updated January 05, 2025)
The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to overwrite CSS, update the trial settings, purge the cache, and find attachments.
0
Attacker Value
Unknown

CVE-2024-4190

Disclosure Date: June 11, 2024 (last updated June 12, 2024)
Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited.
0
Attacker Value
Unknown

CVE-2024-5813

Disclosure Date: June 11, 2024 (last updated February 12, 2025)
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
Attacker Value
Unknown

CVE-2024-5812

Disclosure Date: June 11, 2024 (last updated February 12, 2025)
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
Attacker Value
Unknown

CVE-2024-4220

Disclosure Date: June 04, 2024 (last updated June 12, 2024)
Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.
Attacker Value
Unknown

CVE-2024-4219

Disclosure Date: June 04, 2024 (last updated June 12, 2024)
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.
Attacker Value
Unknown

CVE-2024-3482

Disclosure Date: May 20, 2024 (last updated May 21, 2024)
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.
0
Attacker Value
Unknown

CVE-2024-2835

Disclosure Date: May 20, 2024 (last updated May 21, 2024)
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.
0
Attacker Value
Unknown

CVE-2024-30048

Disclosure Date: May 14, 2024 (last updated January 12, 2025)
Dynamics 365 Customer Insights Spoofing Vulnerability