5.4

CVSS3.1

CVE-2024-53966 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 11:40 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 4:05 p.m.

5.4

CVSS3.1

CVE-2024-53964 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 11:40 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 4:05 p.m.

5.4

CVSS3.1

CVE-2024-53965 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 11:39 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 4:05 p.m.

7.8

CVSS3.0

CVE-2025-0413 - Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability

Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the targetโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 11:09 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 12:45 p.m.

7.8

CVSS3.1

CVE-2024-11468 -

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS โ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 10:17 p.m. ๐Ÿ”„ Last Modified: Feb. 5, 2025, 4:15 p.m.

8.4

CVSS4.0

CVE-2023-39943 - Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds Write

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the โ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 10:15 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 4:59 p.m.

8.4

CVSS4.0

CVE-2023-40222 - Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Heap-based Buffer Overflow

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context oโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 10:13 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 4:54 p.m.

7.8

CVSS3.1

CVE-2024-11467 -

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw.ย Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.

๐Ÿ“… Published: Feb. 4, 2025, 10:12 p.m. ๐Ÿ”„ Last Modified: Feb. 5, 2025, 3:15 p.m.

5.4

CVSS3.1

CVE-2024-13722 - Checkmk NagVis Reflected Cross-site Scripting

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

๐Ÿ“… Published: Feb. 4, 2025, 10:04 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

7.2

CVSS3.1

CVE-2024-13723 - Checkmk NagVis Remote Code Execution

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.

๐Ÿ“… Published: Feb. 4, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.
Total resulsts: 344059
Page 6335 of 34,406
ยซ previous page ยป next page
Filters