Show filters
917 Total Results
Displaying 91-100 of 917
Sort by:
Attacker Value
Unknown

CVE-2024-6881

Disclosure Date: July 29, 2024 (last updated August 09, 2024)
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
Attacker Value
Unknown

CVE-2024-6124

Disclosure Date: July 29, 2024 (last updated August 09, 2024)
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session
Attacker Value
Unknown

CVE-2024-37552

Disclosure Date: July 21, 2024 (last updated September 06, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Inisev Social Media & Share Icons allows Stored XSS.This issue affects Social Media & Share Icons: from n/a through 2.9.1.
Attacker Value
Unknown

CVE-2024-37551

Disclosure Date: July 21, 2024 (last updated September 06, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Perials Simple Social Share allows Stored XSS.This issue affects Simple Social Share: from n/a through 3.0.
Attacker Value
Unknown

CVE-2024-21122

Disclosure Date: July 16, 2024 (last updated January 05, 2025)
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared Components. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise HCM Shared Components, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Shared Components accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM Shared Components accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
0
Attacker Value
Unknown

CVE-2024-6557

Disclosure Date: July 16, 2024 (last updated January 05, 2025)
The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.1.3. This is due the plugin utilizing the wpdeveloper library and leaving the demo files in place with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
0
Attacker Value
Unknown

CVE-2024-38094

Disclosure Date: July 09, 2024 (last updated January 28, 2025)
Microsoft SharePoint Remote Code Execution Vulnerability
0
Attacker Value
Unknown

CVE-2024-38024

Disclosure Date: July 09, 2024 (last updated July 12, 2024)
Microsoft SharePoint Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-32987

Disclosure Date: July 09, 2024 (last updated July 18, 2024)
Microsoft SharePoint Server Information Disclosure Vulnerability
Attacker Value
Unknown

CVE-2024-3228

Disclosure Date: July 09, 2024 (last updated August 08, 2024)
The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' class. This makes it possible for unauthenticated attackers to view limited content from password protected posts.