Show filters
335,472 Total Results
Displaying 661-670 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2024-11312
Disclosure Date: November 18, 2024 (last updated November 21, 2024)
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
0
Attacker Value
Unknown
CVE-2024-11311
Disclosure Date: November 18, 2024 (last updated November 21, 2024)
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
0
Attacker Value
Unknown
CVE-2024-5030
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack
0
Attacker Value
Unknown
CVE-2024-52947
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin
0
Attacker Value
Unknown
CVE-2024-52946
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
0
Attacker Value
Unknown
CVE-2024-52945
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context.
0
Attacker Value
Unknown
CVE-2024-52944
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
0
Attacker Value
Unknown
CVE-2024-52943
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
0
Attacker Value
Unknown
CVE-2024-52942
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
0
Attacker Value
Unknown
CVE-2024-52941
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
0