Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Low
CVE-2019-11358
Disclosure Date: April 20, 2019 (last updated February 17, 2024)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
6
Attacker Value
Moderate
CVE-2015-9251
Disclosure Date: January 18, 2018 (last updated November 08, 2023)
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
6
Attacker Value
Unknown
CVE-2024-0068
Disclosure Date: February 29, 2024 (last updated March 01, 2024)
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue affects Workforce Access: before 8.7.1.
0
Attacker Value
Unknown
CVE-2023-6336
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.
0
Attacker Value
Unknown
CVE-2023-6335
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.
0
Attacker Value
Unknown
CVE-2023-6334
Disclosure Date: January 16, 2024 (last updated September 26, 2024)
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Access: before 8.7.
0
Attacker Value
Unknown
CVE-2023-5097
Disclosure Date: January 16, 2024 (last updated September 26, 2024)
Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.
0
Attacker Value
Unknown
CVE-2023-0834
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects Workforce Access: from 6.12 before 8.1.
0
Attacker Value
Unknown
CVE-2022-3258
Disclosure Date: November 03, 2022 (last updated December 22, 2024)
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.
0
Attacker Value
Unknown
CVE-2022-1984
Disclosure Date: July 19, 2022 (last updated February 24, 2025)
This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated attackers to elevate privileges via a malicious serialized payload.
0