7.8

CVSS3.1

CVE-2024-11468 -

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS …

📅 Published: Feb. 4, 2025, 10:17 p.m. 🔄 Last Modified: Feb. 5, 2025, 4:15 p.m.

8.4

CVSS4.0

CVE-2023-39943 - Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds Write

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the …

📅 Published: Feb. 4, 2025, 10:15 p.m. 🔄 Last Modified: Sept. 16, 2025, 4:59 p.m.

8.4

CVSS4.0

CVE-2023-40222 - Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Heap-based Buffer Overflow

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context o…

📅 Published: Feb. 4, 2025, 10:13 p.m. 🔄 Last Modified: Sept. 16, 2025, 4:54 p.m.

7.8

CVSS3.1

CVE-2024-11467 -

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.

📅 Published: Feb. 4, 2025, 10:12 p.m. 🔄 Last Modified: Feb. 5, 2025, 3:15 p.m.

5.4

CVSS3.1

CVE-2024-13722 - Checkmk NagVis Reflected Cross-site Scripting

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

📅 Published: Feb. 4, 2025, 10:04 p.m. 🔄 Last Modified: Nov. 3, 2025, 8:16 p.m.

7.2

CVSS3.1

CVE-2024-13723 - Checkmk NagVis Remote Code Execution

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.

📅 Published: Feb. 4, 2025, 10:02 p.m. 🔄 Last Modified: Nov. 3, 2025, 8:16 p.m.

5.4

CVSS4.0

CVE-2024-8125 - A remote code vulnerability has been discovered in OpenText™ Content Management.

Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection.  A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the…

📅 Published: Feb. 4, 2025, 9:27 p.m. 🔄 Last Modified: Feb. 4, 2025, 10:15 p.m.

4.3

CVSS3.1

CVE-2024-53266 - Cross-site Scripting (XSS) via topic titles when CSP disabled in Discourse

Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, and with CSP disabled, activity streams in the user's profile page may be vulnerable to XSS. This has been patched in the latest version of Discourse core. Users are advised to upg…

📅 Published: Feb. 4, 2025, 9:18 p.m. 🔄 Last Modified: Sept. 25, 2025, 8:27 p.m.

4.3

CVSS3.1

CVE-2024-53851 - Partial denial of service via inline oneboxes in Discourse

Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline oneboxes for URLs wasn't enforcing limits on the number of URLs that it accepted, allowing a malicious user to inflict denial of service on some parts of the app. This vulnerabilit…

📅 Published: Feb. 4, 2025, 9:16 p.m. 🔄 Last Modified: Sept. 26, 2025, 1:04 p.m.

4.3

CVSS3.1

CVE-2024-53994 - Potential bypass of chat permissions in Discourse

Discourse is an open source platform for community discussion. In affected versions users who disable chat in preferences could still be reachable in some cases. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable th…

📅 Published: Feb. 4, 2025, 9:12 p.m. 🔄 Last Modified: Sept. 25, 2025, 8:27 p.m.
Total resulsts: 343975
Page 6327 of 34,398
« previous page » next page
Filters