6.4

CVSS3.1

CVE-2024-37900 - XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to get the victim into uploading a file with a mali…

πŸ“… Published: July 31, 2024, 3:15 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 4:54 p.m.

4.3

CVSS3.1

CVE-2024-37898 - XWiki Platform vulnerable to document deletion and overwrite from edit

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having delete right. The previous version of the page …

πŸ“… Published: July 31, 2024, 3:12 p.m. πŸ”„ Last Modified: Sept. 6, 2024, 9:16 p.m.

8.8

CVSS3.1

CVE-2024-7340 - W&B Weave server remote arbitrary file leak and privilege escalation

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.

πŸ“… Published: July 31, 2024, 3 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2024-37135 -

DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application …

πŸ“… Published: July 31, 2024, 2 p.m. πŸ”„ Last Modified: Nov. 22, 2024, 6:15 p.m.

3.3

CVSS3.1

CVE-2024-31203 -

A β€œCWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component.

πŸ“… Published: July 31, 2024, 1:18 p.m. πŸ”„ Last Modified: Sept. 30, 2024, 3:15 p.m.

7.8

CVSS3.1

CVE-2024-31202 -

A β€œCWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

πŸ“… Published: July 31, 2024, 1:17 p.m. πŸ”„ Last Modified: Sept. 30, 2024, 3:15 p.m.

6.5

CVSS3.1

CVE-2024-31201 -

A β€œCWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.

πŸ“… Published: July 31, 2024, 1:17 p.m. πŸ”„ Last Modified: Aug. 12, 2024, 6:46 p.m.

4.2

CVSS3.1

CVE-2024-31200 -

A β€œCWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser.

πŸ“… Published: July 31, 2024, 1:16 p.m. πŸ”„ Last Modified: Aug. 12, 2024, 6:25 p.m.

8.8

CVSS3.1

CVE-2024-31199 -

A β€œCWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.

πŸ“… Published: July 31, 2024, 1:16 p.m. πŸ”„ Last Modified: Sept. 30, 2024, 2:15 p.m.

8.3

CVSS3.1

CVE-2024-3083 -

A β€œCWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a malicious web page.

πŸ“… Published: July 31, 2024, 1:15 p.m. πŸ”„ Last Modified: Sept. 30, 2024, 2:15 p.m.
Total resulsts: 346671
Page 8736 of 34,668
Β« previous page Β» next page
Filters