1171
|
- |
|
-
|
-
|
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module i…
|
-
|
CVE-2023-52268
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1172
|
- |
|
-
|
-
|
A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authenti…
|
CWE-384
Session Fixation
|
CVE-2023-50176
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1173
|
- |
|
-
|
-
|
An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other o…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2023-47543
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1174
|
- |
|
-
|
-
|
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged…
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2023-44255
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1175
|
- |
|
-
|
-
|
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording serv…
|
-
|
CVE-2024-8069
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1176
|
- |
|
-
|
-
|
An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-co…
|
-
|
CVE-2024-51720
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1177
|
7.3 |
HIGH
Network
|
-
|
-
|
Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network.
|
CWE-302
Authentication Bypass by Assumed-Immutable Data
|
CVE-2024-49056
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1178
|
7.8 |
HIGH
Local
|
-
|
-
|
Microsoft PC Manager Elevation of Privilege Vulnerability
|
CWE-59
Link Following
|
CVE-2024-49051
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1179
|
8.8 |
HIGH
Network
|
-
|
-
|
Visual Studio Code Python Extension Remote Code Execution Vulnerability
|
CWE-501
Trust Boundary Violation
|
CVE-2024-49050
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1180
|
7.1 |
HIGH
Local
|
-
|
-
|
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
|
CWE-284
Improper Access Control
|
CVE-2024-49049
|
2024-11-14 02:01 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|