4.3
CVE-2024-38093 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
5.4
CVE-2024-37897 - Insufficient access control for password reset in sftpgo
SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and WebClient support password reset. This feature is disabled in the default configuration. In SFTPGo versions prior to v2.6.1, if the feature is enabled,…
4.5
CVE-2024-37352 - Cross-site scripting vulnerability in the Absolute Secure Access administrative console prior to 13…
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that allows attackers with system administrator permissions to interfere with other system administrators’ use of the management UI when the second administrator accesses the vulnerab…
4.5
CVE-2024-37351 - Cross-site scripting vulnerability in the Absolute Secure Access administrative console prior to 13…
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with other system administrator’s use of the management UI when the second administrator later edits the same management…
0.0
CVE-2024-6211 -
loading template...
6.5
CVE-2024-37350 - Cross-site scripting vulnerability in the Absolute Secure Access administrative console prior to 13…
There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.06. Attackers can interfere with a system administrator’s use of the policy management UI when the attacker convinces the victim administrator to follow a crafted link to the vuln…
4.5
CVE-2024-37349 - Cross-site scripting vulnerability in the Absolute Secure Access administrative console prior to 13…
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with other system administrator’s use of the management UI when the victim administrator edits the same management objec…
4.5
CVE-2024-37348 - Cross-site scripting vulnerability in the Absolute Secure Access administrative console prior to 13…
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the management UI when the second administrator later edits the same manageme…
4.5
CVE-2024-37347 - Cross-site scripting vulnerability in the Absolute Secure Access administrative console prior to 13…
There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can pass a limited length script to be run by another administrator. The scope is unchanged, there is no l…
4.9
CVE-2024-37346 - Insufficient input validation vulnerability in the Absolute Secure Access Warehouse prior to 13.06
There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid data to the warehous…