Show filters
863 Total Results
Displaying 81-90 of 863
Sort by:
Attacker Value
Unknown

CVE-2024-20395

Disclosure Date: July 17, 2024 (last updated July 18, 2024)
A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This vulnerability is due to insecure transmission of requests to backend services when the app accesses embedded media, such as images. An attacker could exploit this vulnerability by sending a message with embedded media that is stored on a messaging server to a targeted user. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture session token information from insecurely transmitted requests and possibly reuse the captured session information to take further actions as the targeted user.
0
Attacker Value
Unknown

CVE-2024-38704

Disclosure Date: July 12, 2024 (last updated July 13, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DynamicWebLab WordPress Team Manager allows PHP Local File Inclusion.This issue affects WordPress Team Manager: from n/a through 2.1.12.
0
Attacker Value
Unknown

CVE-2024-37997

Disclosure Date: July 09, 2024 (last updated October 08, 2024)
A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (All versions < V7.1.0.014), Teamcenter Visualization V14.2 (All versions < V14.2.0.13), Teamcenter Visualization V14.3 (All versions < V14.3.0.11), Teamcenter Visualization V2312 (All versions < V2312.0008), Teamcenter Visualization V2406 (All versions < V2406.0003). The affected applications contain a stack based overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-37996

Disclosure Date: July 09, 2024 (last updated October 08, 2024)
A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (All versions < V7.1.0.014), Teamcenter Visualization V14.2 (All versions < V14.2.0.13), Teamcenter Visualization V14.3 (All versions < V14.3.0.11), Teamcenter Visualization V2312 (All versions < V2312.0008), Teamcenter Visualization V2406 (All versions < V2406.0003). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted XML files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
0
Attacker Value
Unknown

CVE-2024-37454

Disclosure Date: July 09, 2024 (last updated August 30, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AWSM Innovations AWSM Team allows Path Traversal.This issue affects AWSM Team: from n/a through 1.3.1.
Attacker Value
Unknown

CVE-2024-39879

Disclosure Date: July 01, 2024 (last updated September 18, 2024)
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
Attacker Value
Unknown

CVE-2024-39878

Disclosure Date: July 01, 2024 (last updated September 18, 2024)
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
Attacker Value
Unknown

CVE-2024-36470

Disclosure Date: May 29, 2024 (last updated February 08, 2025)
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
Attacker Value
Unknown

CVE-2024-36378

Disclosure Date: May 29, 2024 (last updated January 28, 2025)
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
Attacker Value
Unknown

CVE-2024-36377

Disclosure Date: May 29, 2024 (last updated January 28, 2025)
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions