Show filters
863 Total Results
Displaying 81-90 of 863
Sort by:
Attacker Value
Unknown
CVE-2024-20395
Disclosure Date: July 17, 2024 (last updated July 18, 2024)
A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information.
This vulnerability is due to insecure transmission of requests to backend services when the app accesses embedded media, such as images. An attacker could exploit this vulnerability by sending a message with embedded media that is stored on a messaging server to a targeted user. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture session token information from insecurely transmitted requests and possibly reuse the captured session information to take further actions as the targeted user.
0
Attacker Value
Unknown
CVE-2024-38704
Disclosure Date: July 12, 2024 (last updated July 13, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DynamicWebLab WordPress Team Manager allows PHP Local File Inclusion.This issue affects WordPress Team Manager: from n/a through 2.1.12.
0
Attacker Value
Unknown
CVE-2024-37997
Disclosure Date: July 09, 2024 (last updated October 08, 2024)
A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (All versions < V7.1.0.014), Teamcenter Visualization V14.2 (All versions < V14.2.0.13), Teamcenter Visualization V14.3 (All versions < V14.3.0.11), Teamcenter Visualization V2312 (All versions < V2312.0008), Teamcenter Visualization V2406 (All versions < V2406.0003). The affected applications contain a stack based overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-37996
Disclosure Date: July 09, 2024 (last updated October 08, 2024)
A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (All versions < V7.1.0.014), Teamcenter Visualization V14.2 (All versions < V14.2.0.13), Teamcenter Visualization V14.3 (All versions < V14.3.0.11), Teamcenter Visualization V2312 (All versions < V2312.0008), Teamcenter Visualization V2406 (All versions < V2406.0003). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted XML files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
0
Attacker Value
Unknown
CVE-2024-37454
Disclosure Date: July 09, 2024 (last updated August 30, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AWSM Innovations AWSM Team allows Path Traversal.This issue affects AWSM Team: from n/a through 1.3.1.
0
Attacker Value
Unknown
CVE-2024-39879
Disclosure Date: July 01, 2024 (last updated September 18, 2024)
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
0
Attacker Value
Unknown
CVE-2024-39878
Disclosure Date: July 01, 2024 (last updated September 18, 2024)
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
0
Attacker Value
Unknown
CVE-2024-36470
Disclosure Date: May 29, 2024 (last updated February 08, 2025)
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
0
Attacker Value
Unknown
CVE-2024-36378
Disclosure Date: May 29, 2024 (last updated January 28, 2025)
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
0
Attacker Value
Unknown
CVE-2024-36377
Disclosure Date: May 29, 2024 (last updated January 28, 2025)
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
0