Show filters
108 Total Results
Displaying 1-10 of 108
Sort by:
Attacker Value
Unknown
CVE-2024-11628
Disclosure Date: February 12, 2025 (last updated February 23, 2025)
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
0
Attacker Value
Unknown
CVE-2024-12057
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end.
By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.
0
Attacker Value
Unknown
CVE-2024-12056
Disclosure Date: December 04, 2024 (last updated December 21, 2024)
The Client secret is not checked when using the OAuth Password grant type.
By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment.
Exploitation requires valid credentials and does not permit the attacker to bypass user privileges.
0
Attacker Value
Unknown
CVE-2024-52810
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) as the minimum consequence. Moreover, the consequences of this vulnerability can escalate to other injection-based attacks, depending on how the library integrates within the application. For instance, if the polluted property propagates to sensitive Node.js APIs (e.g., exec, eval), it could enable an attacker to execute arbitrary commands within the application's context. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2024-52809
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2024-9506
Disclosure Date: October 15, 2024 (last updated October 16, 2024)
Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.
0
Attacker Value
Unknown
CVE-2024-6783
Disclosure Date: July 23, 2024 (last updated July 24, 2024)
A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code.
0
Attacker Value
Unknown
CVE-2023-40704
Disclosure Date: July 18, 2024 (last updated September 06, 2024)
Philips Vue PACS uses default credentials for potentially critical functionality.
0
Attacker Value
Unknown
CVE-2023-40539
Disclosure Date: July 18, 2024 (last updated September 06, 2024)
Philips Vue PACS does not require that users have strong passwords, which could make it easier for attackers to compromise user accounts.
0
Attacker Value
Unknown
CVE-2023-40223
Disclosure Date: July 18, 2024 (last updated September 06, 2024)
Philips Vue PACS does not properly assign, modify, track, or check actor privileges, creating an unintended sphere of control for that actor.
0