CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2024-7103

Description: A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input validation. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the login flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser. While this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.

CVSS: MEDIUM (4.6)

EPSS Score: 0.03%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)

CVE-2024-51553

Description: Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)

CVE-2024-51552

Description: Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS: MEDIUM (6.0)

EPSS Score: 0.05%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)

CVE-2024-48848

Description: Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS: MEDIUM (6.5)

EPSS Score: 0.04%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)

CVE-2024-13958

Description: Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS: MEDIUM (4.6)

EPSS Score: 0.03%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)

CVE-2024-13956

Description: SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS: MEDIUM (6.7)

EPSS Score: 0.05%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)

CVE-2024-13954

Description: Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)

CVE-2024-13953

Description: Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS: MEDIUM (4.9)

EPSS Score: 0.04%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)

CVE-2024-13950

Description: Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS: MEDIUM (6.8)

EPSS Score: 0.04%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)

CVE-2024-13949

Description: Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS: MEDIUM (6.9)

EPSS Score: 0.03%

SSVC Exploitation: none

Source: CVE
May 22nd, 2025 (28 days ago)