Show filters
13,160 Total Results
Displaying 601-610 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-26049

Disclosure Date: June 13, 2024 (last updated August 08, 2024)
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Attacker Value
Unknown

CVE-2024-5661

Disclosure Date: June 13, 2024 (last updated July 03, 2024)
An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.
Attacker Value
Unknown

CVE-2024-4149

Disclosure Date: June 13, 2024 (last updated July 03, 2024)
The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2024-4145

Disclosure Date: June 13, 2024 (last updated July 03, 2024)
The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi-site network).
Attacker Value
Unknown

CVE-2024-5906

Disclosure Date: June 12, 2024 (last updated August 08, 2024)
A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in the context of another user's browser when accessed by that other user.
Attacker Value
Unknown

CVE-2024-5558

Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.
Attacker Value
Unknown

CVE-2024-5557

Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.
Attacker Value
Unknown

CVE-2024-28970

Disclosure Date: June 12, 2024 (last updated September 19, 2024)
Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial of service.
Attacker Value
Unknown

CVE-2024-28024

Disclosure Date: June 11, 2024 (last updated August 16, 2024)
A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere.
Attacker Value
Unknown

CVE-2024-23111

Disclosure Date: June 11, 2024 (last updated August 23, 2024)
An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.