Show filters
335,472 Total Results
Displaying 661-670 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-11312

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Attacker Value
Unknown

CVE-2024-11311

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Attacker Value
Unknown

CVE-2024-5030

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack
0
Attacker Value
Unknown

CVE-2024-52947

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin
0
Attacker Value
Unknown

CVE-2024-52946

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
0
Attacker Value
Unknown

CVE-2024-52945

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context.
0
Attacker Value
Unknown

CVE-2024-52944

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
0
Attacker Value
Unknown

CVE-2024-52943

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
0
Attacker Value
Unknown

CVE-2024-52942

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
0
Attacker Value
Unknown

CVE-2024-52941

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
0