4.6

CVSS3.1

CVE-2024-41943 - I, Librarian Stored XSS vulnerability in Item Summary

I, Librarian is an open-source version of a PDF managing SaaS. PDF notes are displayed on the Item Summary page without any form of validation or sanitation. An attacker can exploit this vulnerability by inserting a payload in the PDF notes that contains malicious code or script. This code will the…

πŸ“… Published: July 30, 2024, 5:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-41916 - Authenticated Sensitive Information Disclosure in ClearPass Policy Manager

A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network serv…

πŸ“… Published: July 30, 2024, 5:09 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:33 a.m.

7.2

CVSS3.1

CVE-2024-41915 - Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in t…

πŸ“… Published: July 30, 2024, 5:07 p.m. πŸ”„ Last Modified: April 7, 2025, 3 p.m.

3.7

CVSS3.1

CVE-2022-33167 - IBM Security Directory Integrator information disclosure

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cook…

πŸ“… Published: July 30, 2024, 5:05 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 7:07 a.m.

5.8

CVSS3.1

CVE-2024-5486 - Authenticated Sensitive Information Disclosure in ClearPass Policy Manager

A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network serv…

πŸ“… Published: July 30, 2024, 5:04 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

6.5

CVSS3.1

CVE-2024-7208 - CVE-2024-7208

A vulnerability in multi-tenant hosting allows an authenticated sender to spoof the identity of a shared, hosted domain, thus bypass security measures provided by DMARC (or SPF or DKIM) policies.

πŸ“… Published: July 30, 2024, 5:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-7209 - CVE-2024-7209

A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof the email identify of the sender.

πŸ“… Published: July 30, 2024, 5:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2023-26288 - IBM Aspera Orchestrator session fixation

IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.

πŸ“… Published: July 30, 2024, 5:01 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 7:51 a.m.

6.5

CVSS3.1

CVE-2023-38001 - IBM Aspera Orchestrator cross-site request forgery

IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 260206.

πŸ“… Published: July 30, 2024, 4:54 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:12 a.m.

5.4

CVSS3.1

CVE-2023-26289 - IBM Aspera Orchestrator HTTP header injection

IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Forc…

πŸ“… Published: July 30, 2024, 4:50 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 7:51 a.m.
Total resulsts: 346515
Page 8729 of 34,652
Β« previous page Β» next page
Filters