Search Results (85877 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-7024 1 Google 1 Chrome 2025-01-02 9.3 Critical
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
CVE-2024-55541 3 Acronis, Linux, Microsoft 3 Cyber Protect, Linux Kernel, Windows 2025-01-02 6.1 Medium
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
CVE-2024-9121 1 Google 1 Chrome 2025-01-02 8.8 High
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVE-2024-27104 1 Glpi-project 1 Glpi 2025-01-02 4.5 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard will be subject to an XSS attack. This issue has been patched in version 10.0.13.
CVE-2024-27914 1 Glpi-project 1 Glpi 2025-01-02 5.3 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar. This issue has been patched in version 10.0.13.
CVE-2024-1474 1 Progress 1 Ws Ftp Server 2025-01-02 7.5 High
In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.
CVE-2023-35621 1 Microsoft 1 Dynamics 365 2025-01-01 7.5 High
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
CVE-2023-36019 1 Microsoft 2 Azure Logic Apps, Power Platform 2025-01-01 9.6 Critical
Microsoft Power Platform Connector Spoofing Vulnerability
CVE-2023-36020 1 Microsoft 1 Dynamics 365 2025-01-01 7.6 High
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-29345 1 Microsoft 1 Edge Chromium 2025-01-01 6.1 Medium
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2023-35308 1 Microsoft 16 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 13 more 2025-01-01 6.5 Medium
Windows MSHTML Platform Security Feature Bypass Vulnerability
CVE-2023-29347 1 Microsoft 1 Windows Admin Center 2025-01-01 8.7 High
Windows Admin Center Spoofing Vulnerability
CVE-2023-21565 1 Microsoft 1 Azure Devops Server 2025-01-01 7.1 High
Azure DevOps Server Spoofing Vulnerability
CVE-2023-24896 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Dynamics 365 Finance Spoofing Vulnerability
CVE-2023-23383 1 Microsoft 1 Azure Service Fabric 2025-01-01 8.2 High
Service Fabric Explorer Spoofing Vulnerability
CVE-2023-21564 1 Microsoft 1 Azure Devops Server 2025-01-01 7.1 High
Azure DevOps Server Cross-Site Scripting Vulnerability
CVE-2023-21805 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2025-01-01 7.8 High
Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2023-21800 1 Microsoft 3 Windows Server 2008, Windows Server 2008 R2, Windows Server 2008 Sp2 2025-01-01 7.8 High
Windows Installer Elevation of Privilege Vulnerability
CVE-2023-21573 1 Microsoft 1 Dynamics 365 2025-01-01 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-21572 1 Microsoft 1 Dynamics 365 2025-01-01 6.5 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability