391
|
9.1 |
CRITICAL
Network
-
|
-
|
A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote attacker to access the web interface with administrative privileges.
This vul…
New
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2023-20154
|
2024-11-16 00:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
392
|
8.6 |
HIGH
Network
-
|
-
|
A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition.
…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2023-20125
|
2024-11-16 00:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
393
|
7.0 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_8.1 windows_7 windows_rt_8.1 windows_10_1909 windows_10_21h1 windows_10_20h2 windows_11_21h2 windows_10_21h2 windows_10_1…
|
Windows User Profile Service Elevation of Privilege Vulnerability
|
CWE-59
Link Following
|
CVE-2022-21919
|
2024-11-15 23:35 |
2022-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
394
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1909 windows_10_21h1 windows_10_20h2 windows_11_21h2 windows_10_21h2 windows_server_2022 windows_server_20h2 windows_server_2019 windows_10_1809
|
Win32k Elevation of Privilege Vulnerability
|
CWE-787
Out-of-bounds Write
|
CVE-2022-21882
|
2024-11-15 23:35 |
2022-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
395
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019 windows_server_2022 windows_10_1607 windows_10_1809 …
|
Why is Microsoft republishing a CVE from 2013?
We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCh…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2013-3900
|
2024-11-15 23:34 |
2013-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
396
|
- |
|
-
|
-
|
A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /database.php of the component Banco de Dados Tab. …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-11240
|
2024-11-15 23:23 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
397
|
- |
|
-
|
-
|
A vulnerability has been found in Landray EKP up to 16.0 and classified as critical. This vulnerability affects the function deleteFile of the file /sys/common/import.do?method=deleteFile of the comp…
|
CWE-22
Path Traversal
|
CVE-2024-11239
|
2024-11-15 23:23 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
398
|
- |
|
-
|
-
|
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.
|
-
|
CVE-2024-52553
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
399
|
- |
|
-
|
-
|
Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability…
|
-
|
CVE-2024-52552
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
400
|
- |
|
-
|
-
|
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing att…
|
-
|
CVE-2024-52551
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|