CVE-2023-34254 |
Description: The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task against an Unix platform with ssh command, an administrator user on the remote can manage to inject a command in a specific workflow the agent would run with the privileges it uses. In the case, the agent is running with administration privileges, a malicious user could gain high privileges on the computer glpi-agent is running on. A malicious user could also disclose all remote accesses the agent is configured with for remoteinventory task. This vulnerability has been patched in glpi-agent 1.5.
CVSS: HIGH (7.7) EPSS Score: 0.19%
November 28th, 2024 (5 months ago)
|
CVE-2023-34240 |
Description: Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system security. Versions of cloudexplorer-lite prior to 1.2.0 did not enforce strong passwords. This vulnerability has been fixed in version 1.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS: MEDIUM (6.5) EPSS Score: 0.14%
November 28th, 2024 (5 months ago)
|
CVE-2023-33905 |
|
CVE-2023-33795 |
Description: A stored cross-site scripting (XSS) vulnerability in the Create Contact Roles (/tenancy/contact-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CVSS: LOW (0.0) EPSS Score: 0.06%
November 28th, 2024 (5 months ago)
|
CVE-2023-33785 |
Description: A stored cross-site scripting (XSS) vulnerability in the Create Rack Roles (/dcim/rack-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CVSS: LOW (0.0) EPSS Score: 0.06%
November 28th, 2024 (5 months ago)
|
CVE-2023-33661 |
|
CVE-2023-33592 |
|
CVE-2023-33570 |
|
CVE-2023-33336 |
|
CVE-2023-33298 |
|