Show filters
13,164 Total Results
Displaying 631-640 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-5656

Disclosure Date: June 06, 2024 (last updated June 13, 2024)
** REJECT ** Accidental duplicate assignment of CVE-2024-4755. Please use CVE-2024-4755.
Attacker Value
Unknown

CVE-2024-4942

Disclosure Date: June 06, 2024 (last updated July 24, 2024)
The Custom Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Attacker Value
Unknown

CVE-2024-0912

Disclosure Date: June 06, 2024 (last updated July 19, 2024)
Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions
Attacker Value
Unknown

CVE-2024-27381

Disclosure Date: June 05, 2024 (last updated June 28, 2024)
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_ut(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.
Attacker Value
Unknown

CVE-2024-27380

Disclosure Date: June 05, 2024 (last updated June 28, 2024)
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_set_delayed_wakeup_type(), there is no input validation check on a length of ioctl_args->args[i] coming from userspace, which can lead to a heap over-read.
Attacker Value
Unknown

CVE-2024-4812

Disclosure Date: June 05, 2024 (last updated June 19, 2024)
A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when opening certain pages, for example, Host Collections.
Attacker Value
Unknown

CVE-2024-29004

Disclosure Date: June 04, 2024 (last updated June 07, 2024)
The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.
Attacker Value
Unknown

CVE-2024-35655

Disclosure Date: June 04, 2024 (last updated June 12, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brave Brave Popup Builder allows Stored XSS.This issue affects Brave Popup Builder: from n/a through 0.6.9.
Attacker Value
Unknown

CVE-2024-35634

Disclosure Date: June 04, 2024 (last updated June 11, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce – Recent Purchases allows PHP Local File Inclusion.This issue affects Woocommerce – Recent Purchases: from n/a through 1.0.1.
Attacker Value
Unknown

CVE-2024-34792

Disclosure Date: June 04, 2024 (last updated June 11, 2024)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping allows Command Injection.This issue affects Dextaz Ping: from n/a through 0.65.