Show filters
461 Total Results
Displaying 71-80 of 461
Sort by:
Attacker Value
Unknown
CVE-2023-6072
Disclosure Date: February 13, 2024 (last updated October 08, 2024)
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard.
0
Attacker Value
Unknown
CVE-2023-47132
Disclosure Date: February 08, 2024 (last updated February 16, 2024)
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.
0
Attacker Value
Unknown
CVE-2024-22108
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value.
0
Attacker Value
Unknown
CVE-2024-22107
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an arbitrary command and compromise the platform.
0
Attacker Value
Unknown
CVE-2023-51838
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.
0
Attacker Value
Unknown
CVE-2023-47564
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.
We have already fixed the vulnerability in the following versions:
Qsync Central 4.4.0.15 ( 2024/01/04 ) and later
Qsync Central 4.3.0.11 ( 2024/01/11 ) and later
0
Attacker Value
Unknown
CVE-2024-1143
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.
0
Attacker Value
Unknown
CVE-2023-51837
Disclosure Date: January 30, 2024 (last updated February 06, 2024)
Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.
0
Attacker Value
Unknown
CVE-2023-51842
Disclosure Date: January 29, 2024 (last updated February 07, 2024)
An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.
0
Attacker Value
Unknown
CVE-2023-52331
Disclosure Date: January 23, 2024 (last updated January 31, 2024)
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
0