Show filters
976 Total Results
Displaying 71-80 of 976
Sort by:
Attacker Value
Unknown
CVE-2024-37312
Disclosure Date: June 14, 2024 (last updated February 26, 2025)
user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user backend is upgraded to 3.0.0 (Nextcloud 20-23), 4.0.0 (Nexcloud 24) or 5.0.0 (Nextcloud 25-28).
0
Attacker Value
Unknown
CVE-2024-5995
Disclosure Date: June 14, 2024 (last updated February 26, 2025)
The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused.
0
Attacker Value
Unknown
CVE-2024-32146
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1.
0
Attacker Value
Unknown
CVE-2024-22279
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade
the service availability of the Cloud Foundry deployment if performed at scale.
0
Attacker Value
Unknown
CVE-2022-45176
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving them on the server. In addition, crafted JavaScript content can then be reflected back to the end user and executed by the web browser.
0
Attacker Value
Unknown
CVE-2022-45168
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate the backup codes before checking the TOTP.
0
Attacker Value
Unknown
CVE-2022-45171
Disclosure Date: May 28, 2024 (last updated February 26, 2025)
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote user, authenticated to the product, can arbitrarily upload potentially dangerous files without restrictions.
0
Attacker Value
Unknown
CVE-2024-5166
Disclosure Date: May 22, 2024 (last updated February 26, 2025)
An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.
0
Attacker Value
Unknown
CVE-2024-0453
Disclosure Date: May 22, 2024 (last updated January 05, 2025)
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete files from a linked OpenAI account.
0
Attacker Value
Unknown
CVE-2024-0452
Disclosure Date: May 22, 2024 (last updated January 05, 2025)
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files to a linked OpenAI account.
0