5.4

CVSS3.1

CVE-2024-53965 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 11:39 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 4:05 p.m.

7.8

CVSS3.0

CVE-2025-0413 - Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability

Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the targetโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 11:09 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 12:45 p.m.

7.8

CVSS3.1

CVE-2024-11468 -

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS โ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 10:17 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2023-39943 - Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds Write

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the โ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 10:15 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 4:59 p.m.

8.4

CVSS4.0

CVE-2023-40222 - Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Heap-based Buffer Overflow

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context oโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 10:13 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 4:54 p.m.

7.8

CVSS3.1

CVE-2024-11467 -

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw.ย Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.

๐Ÿ“… Published: Feb. 4, 2025, 10:12 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-13722 - Checkmk NagVis Reflected Cross-site Scripting

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

๐Ÿ“… Published: Feb. 4, 2025, 10:04 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-13723 - Checkmk NagVis Remote Code Execution

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.

๐Ÿ“… Published: Feb. 4, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS4.0

CVE-2024-8125 - A remote code vulnerability has been discovered in OpenTextโ„ข Content Management.

Improper Validation of Specified Type of Input vulnerability in OpenTextโ„ข Content Management (Extended ECM) allows Parameter Injection.ย  A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on theโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 9:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-53266 - Cross-site Scripting (XSS) via topic titles when CSP disabled in Discourse

Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, and with CSP disabled, activity streams in the user's profile page may be vulnerable to XSS. This has been patched in the latest version of Discourse core. Users are advised to upgโ€ฆ

๐Ÿ“… Published: Feb. 4, 2025, 9:18 p.m. ๐Ÿ”„ Last Modified: Sept. 25, 2025, 8:27 p.m.
Total resulsts: 344998
Page 6429 of 34,500
ยซ previous page ยป next page
Filters