4.8

CVSS3.1

CVE-2024-25707 - BUG-000160241 - Reflected XSS in Portal for ArcGIS

There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted string which could potentially execute arbitrary JavaScript code in the their own browser (Self XSS). A u…

📅 Published: Oct. 4, 2024, 5:16 p.m. 🔄 Last Modified: April 10, 2025, 7:14 p.m.

5.4

CVSS3.1

CVE-2024-38036 - BUG-000154827 - Reflected XSS in ArcGIS Experience Builder

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

📅 Published: Oct. 4, 2024, 5:16 p.m. 🔄 Last Modified: April 10, 2025, 7:15 p.m.

4.6

CVSS3.1

CVE-2024-8149 - BUG-000168624 - Unvalidated redirect in Portal for ArcGIS.

There is a reflected Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.1 and 11.2 that may allow a remote, authenticated attacker with low‑privileged access to create a crafted link which, when clicked, could potentially execute arbitrary JavaScript code in the victim’s…

📅 Published: Oct. 4, 2024, 5:14 p.m. 🔄 Last Modified: Feb. 13, 2026, 7:41 p.m.

5.4

CVSS3.1

CVE-2024-38039 - BUG-000161683 - HTML injection vulnerability in Portal for ArcGIS.

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).

📅 Published: Oct. 4, 2024, 5:13 p.m. 🔄 Last Modified: Oct. 15, 2024, 2:34 p.m.

6.1

CVSS3.1

CVE-2024-8148 - BUG-000168624 - Unvalidated redirect in Portal for ArcGIS. (11.2, 11.1, 10.9.1. and 10.8.1)

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

📅 Published: Oct. 4, 2024, 5:11 p.m. 🔄 Last Modified: April 10, 2025, 7:16 p.m.

6.1

CVSS3.1

CVE-2024-38037 - BUG-000167983 - Unvalidated redirect in Portal for ArcGIS

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

📅 Published: Oct. 4, 2024, 5:10 p.m. 🔄 Last Modified: April 10, 2025, 7:16 p.m.

8.1

CVSS3.1

CVE-2024-47183 - Parse Server's custom object ID allows to acquire role privileges

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acqu…

📅 Published: Oct. 4, 2024, 3:06 p.m. 🔄 Last Modified: Feb. 25, 2026, 5:47 p.m.

7.5

CVSS3.1

CVE-2024-47769 - IDURAR has a Path Traversal (unauthenticated user can read sensitive data)

IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. Using the reference usage here, it is identified that the public endpoint is accessible to an unauthenticated user. The user's input is directly appended to the join statement with…

📅 Published: Oct. 4, 2024, 2:45 p.m. 🔄 Last Modified: Nov. 13, 2024, 3:12 p.m.

6.9

CVSS4.0

CVE-2024-47768 - Lif Authentication Server Has No Auth Check When Updating Password In Account Recovery

Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker …

📅 Published: Oct. 4, 2024, 2:33 p.m. 🔄 Last Modified: Nov. 13, 2024, 2:55 p.m.

6.9

CVSS4.0

CVE-2024-47765 - Minecraft MOTD Parser's HtmlGenerator vulnerable to XSS

Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential cross-site scripting (XSS) attack through a parsed malformed Minecraft server MOTD. The HtmlGenerator iterates through objects of MotdItem that are contained in an object of MotdIt…

📅 Published: Oct. 4, 2024, 2:20 p.m. 🔄 Last Modified: Nov. 13, 2024, 2:48 p.m.
Total resulsts: 342314
Page 7714 of 34,232
« previous page » next page
Filters