Show filters
819 Total Results
Displaying 71-80 of 819
Sort by:
Attacker Value
Unknown

CVE-2024-4706

Disclosure Date: May 23, 2024 (last updated January 05, 2025)
The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2020-35165

Disclosure Date: May 22, 2024 (last updated February 07, 2025)
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
Attacker Value
Unknown

CVE-2024-4067

Disclosure Date: May 14, 2024 (last updated August 28, 2024)
The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.
0
Attacker Value
Unknown

CVE-2024-27086

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
The MSAL library enabled acquisition of security tokens to call protected APIs. MSAL.NET applications targeting Xamarin Android and .NET Android (e.g., MAUI) using the library from versions 4.48.0 to 4.60.0 are impacted by a low severity vulnerability. A malicious application running on a customer Android device can cause local denial of service against applications that were built using MSAL.NET for authentication on the same device (i.e., prevent the user of the legitimate application from logging in) due to incorrect activity export configuration. MSAL.NET version 4.60.1 includes the fix. As a workaround, a developer may explicitly mark the MSAL.NET activity non-exported.
0
Attacker Value
Unknown

CVE-2024-31069

Disclosure Date: April 12, 2024 (last updated April 13, 2024)
IO-1020 Micro ELD web server uses a default password for authentication.
0
Attacker Value
Unknown

CVE-2024-30210

Disclosure Date: April 12, 2024 (last updated April 13, 2024)
IO-1020 Micro ELD uses a default WIFI password that could allow an adjacent attacker to connect to the device.
0
Attacker Value
Unknown

CVE-2024-28878

Disclosure Date: April 12, 2024 (last updated April 13, 2024)
IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without sufficiently verifying the origin or integrity of the code.
0
Attacker Value
Unknown

CVE-2024-22448

Disclosure Date: April 10, 2024 (last updated February 05, 2025)
Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
Attacker Value
Unknown

CVE-2024-28917

Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2023-48674

Disclosure Date: March 01, 2024 (last updated February 01, 2025)
Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.