Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2024-39717Alta7.2
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.
- CVE-2024-28987Critica9.1
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
- CVE-2024-7971Critica9.6
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-7965Alta8.8
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-28000Critica9.8
Vulnerabilità di assegnazione errata dei privilegi in LiteSpeed Technologies LiteSpeed Cache litespeed-cache. Questo problema riguarda LiteSpeed Cache: da n/a fino a <= 6.3.0.1.
- CVE-2024-7262Alta7.8
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document
- CVE-2024-28986Critica9.8
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.
- CVE-2024-7593Critica9.8
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
- CVE-2024-38213Media6.5
Windows Mark of the Web Security Feature Bypass Vulnerability
- CVE-2024-38193Alta7.8
Vulnerabilità di elevazione dei privilegi in Windows Ancillary Function Driver for WinSock
- CVE-2024-38189Alta8.8
Microsoft Project Remote Code Execution Vulnerability
- CVE-2024-38178Alta7.5
Scripting Engine Memory Corruption Vulnerability
- CVE-2024-38107Alta7.8
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
- CVE-2024-38106Alta7.0
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-41710Alta7.2
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
- CVE-2024-27443Media6.1
È stato scoperto un problema in Zimbra Collaboration (ZCS) 9.0 e 10.0. Esiste una vulnerabilità di Cross-Site Scripting (XSS) nella funzionalità CalendarInvite dell'interfaccia utente classic della webmail Zimbra, a causa di una convalida impropria dell'input nella gestione dell'header del calendario. Un attaccante può sfruttarla tramite un messaggio email contenente un header del calendario appositamente predisposto con un payload XSS incorporato. Quando una vittima visualizza questo messaggio nell'interfaccia classic della webmail Zimbra, il payload viene eseguito nel contesto della sessione della vittima, portando potenzialmente all'esecuzione di codice JavaScript arbitrario.
- CVE-2024-7694Alta7.2
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
- CVE-2024-7399Alta8.8
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
- CVE-2024-42009Critica9.3
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
- CVE-2024-38856Critica9.8
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
This product uses the NVD API but is not endorsed or certified by the NVD.