2.3

CVSS4.0

CVE-2024-54133 - Possible Content Security Policy bypass in Action Dispatch

Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) vulnerability in the `content_security_policy` helper starting in version 5.2.0 of Action Pack and prior to versions 7.0.8.7, 7.1.5.1, 7.2.2.1, and 8.0.0.1. Applications which set…

📅 Published: Dec. 10, 2024, 10:52 p.m. 🔄 Last Modified: July 12, 2025, 10:10 p.m.

5.4

CVSS3.1

CVE-2024-52865 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse t…

📅 Published: Dec. 10, 2024, 10:05 p.m. 🔄 Last Modified: Jan. 15, 2025, 5:55 p.m.

5.4

CVSS3.1

CVE-2024-52848 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…

📅 Published: Dec. 10, 2024, 10:05 p.m. 🔄 Last Modified: Dec. 13, 2024, 5:45 p.m.

5.4

CVSS3.1

CVE-2024-43713 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user inpu…

📅 Published: Dec. 10, 2024, 10:05 p.m. 🔄 Last Modified: Dec. 17, 2024, 2:55 p.m.

5.4

CVSS3.1

CVE-2024-43715 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user inpu…

📅 Published: Dec. 10, 2024, 10:05 p.m. 🔄 Last Modified: Dec. 17, 2024, 2:56 p.m.

4.3

CVSS3.1

CVE-2024-43717 - Adobe Experience Manager | Improper Access Control (CWE-284)

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitatio…

📅 Published: Dec. 10, 2024, 10:05 p.m. 🔄 Last Modified: Jan. 15, 2025, 5:39 p.m.

5.4

CVSS3.1

CVE-2024-52836 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…

📅 Published: Dec. 10, 2024, 10:05 p.m. 🔄 Last Modified: Dec. 13, 2024, 4:14 p.m.

5.4

CVSS3.1

CVE-2024-52860 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user inpu…

📅 Published: Dec. 10, 2024, 10:04 p.m. 🔄 Last Modified: Dec. 13, 2024, 5:45 p.m.

5.4

CVSS3.1

CVE-2024-43727 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…

📅 Published: Dec. 10, 2024, 10:04 p.m. 🔄 Last Modified: Dec. 17, 2024, 4:08 p.m.

5.4

CVSS3.1

CVE-2024-52838 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user inpu…

📅 Published: Dec. 10, 2024, 10:04 p.m. 🔄 Last Modified: Dec. 18, 2024, 2:34 p.m.
Total resulsts: 343168
Page 6926 of 34,317
« previous page » next page
Filters