Show filters
917 Total Results
Displaying 81-90 of 917
Sort by:
Attacker Value
Unknown

CVE-2024-38228

Disclosure Date: September 10, 2024 (last updated September 18, 2024)
Microsoft SharePoint Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-38227

Disclosure Date: September 10, 2024 (last updated September 18, 2024)
Microsoft SharePoint Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-38018

Disclosure Date: September 10, 2024 (last updated September 19, 2024)
Microsoft SharePoint Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-8363

Disclosure Date: September 05, 2024 (last updated September 12, 2024)
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and including, 2.02 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-8108

Disclosure Date: August 31, 2024 (last updated September 20, 2024)
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-8338

Disclosure Date: August 30, 2024 (last updated September 26, 2024)
A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /includes/fileReceive.php of the component File Extension Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Attacker Value
Unknown

CVE-2024-43230

Disclosure Date: August 26, 2024 (last updated September 19, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Shared Files – File Upload Form Shared Files.This issue affects Shared Files: from n/a through 1.7.28.
Attacker Value
Unknown

CVE-2024-42377

Disclosure Date: August 13, 2024 (last updated September 13, 2024)
SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application
Attacker Value
Unknown

CVE-2024-42376

Disclosure Date: August 13, 2024 (last updated September 13, 2024)
SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application.
Attacker Value
Unknown

CVE-2023-38018

Disclosure Date: August 12, 2024 (last updated August 30, 2024)
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574.