Show filters
71,468 Total Results
Displaying 691-700 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-0808

Disclosure Date: January 24, 2024 (last updated January 30, 2024)
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2024-0807

Disclosure Date: January 24, 2024 (last updated January 30, 2024)
Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2022-1609

Disclosure Date: January 16, 2024 (last updated January 23, 2024)
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
Attacker Value
Unknown

CVE-2023-46226

Disclosure Date: January 15, 2024 (last updated January 23, 2024)
Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the issue.
Attacker Value
Unknown

CVE-2023-6875

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.
Attacker Value
Unknown

CVE-2024-20700

Disclosure Date: January 09, 2024 (last updated January 12, 2025)
Windows Hyper-V Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-39336

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server.
Attacker Value
Unknown

CVE-2023-51467

Disclosure Date: December 26, 2023 (last updated January 04, 2024)
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
Attacker Value
Unknown

CVE-2023-7101

Disclosure Date: December 24, 2023 (last updated January 10, 2024)
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.
Attacker Value
Unknown

CVE-2023-7024

Disclosure Date: December 21, 2023 (last updated December 28, 2023)
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)