Show filters
13,173 Total Results
Displaying 811-820 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-23591

Disclosure Date: February 16, 2024 (last updated February 20, 2024)
ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS configuration setting. The server’s NIST SP 800-193-compliant Platform Firmware Resiliency (PFR) security subsystem significantly mitigates this issue.
Attacker Value
Unknown

CVE-2024-20720

Disclosure Date: February 15, 2024 (last updated February 17, 2024)
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2024-20719

Disclosure Date: February 15, 2024 (last updated February 17, 2024)
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, that could be leveraged to gain admin access.
Attacker Value
Unknown

CVE-2024-20716

Disclosure Date: February 15, 2024 (last updated February 17, 2024)
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnerability to exhaust system resources, causing the application to slow down or crash. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2023-45581

Disclosure Date: February 15, 2024 (last updated February 21, 2024)
An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests.
Attacker Value
Unknown

CVE-2024-25301

Disclosure Date: February 14, 2024 (last updated April 27, 2024)
Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.
Attacker Value
Unknown

CVE-2024-25300

Disclosure Date: February 14, 2024 (last updated April 27, 2024)
A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Template section.
Attacker Value
Unknown

CVE-2024-25213

Disclosure Date: February 14, 2024 (last updated February 15, 2024)
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.
Attacker Value
Unknown

CVE-2024-25212

Disclosure Date: February 14, 2024 (last updated February 15, 2024)
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.
Attacker Value
Unknown

CVE-2024-24698

Disclosure Date: February 14, 2024 (last updated October 05, 2024)
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.