Show filters
1,078 Total Results
Displaying 81-90 of 1,078
Sort by:
Attacker Value
Unknown
CVE-2024-4302
Disclosure Date: April 29, 2024 (last updated January 05, 2025)
Super 8 Live Chat online customer service platform fails to properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. When the message recipient views the message, they become susceptible to Cross-site Scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2024-3052
Disclosure Date: April 26, 2024 (last updated September 27, 2024)
Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway.
0
Attacker Value
Unknown
CVE-2024-3051
Disclosure Date: April 26, 2024 (last updated September 27, 2024)
Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent by the end device will not be acknowledged by the gateway during this time.
0
Attacker Value
Unknown
CVE-2024-3764
Disclosure Date: April 14, 2024 (last updated April 16, 2024)
** DISPUTED ** ** DISPUTED ** A vulnerability classified as problematic has been found in Tuya SDK up to 5.0.x. Affected is an unknown function of the component MQTT Packet Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. Upgrading to version 5.1.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-260604. NOTE: The vendor explains that a malicious actor would have to crack TLS first or use a legitimate login to initiate the attack.
0
Attacker Value
Unknown
CVE-2023-51395
Disclosure Date: March 07, 2024 (last updated September 26, 2024)
The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-28110
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.
0
Attacker Value
Unknown
CVE-2024-1608
Disclosure Date: February 20, 2024 (last updated February 20, 2024)
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
0
Attacker Value
Unknown
CVE-2022-42443
Disclosure Date: February 17, 2024 (last updated January 23, 2025)
An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploading of files. IBM X-Force ID: 238535.
0
Attacker Value
Unknown
CVE-2024-24699
Disclosure Date: February 14, 2024 (last updated October 05, 2024)
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.
0
Attacker Value
Unknown
CVE-2024-23680
Disclosure Date: January 19, 2024 (last updated January 27, 2024)
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
0