Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-06 CVE-2024-10928 Cross-site Scripting vulnerability in Monocms 1.0
A vulnerability was found in MonoCMS up to 20240528.
network
low complexity
monocms CWE-79
6.1
2024-11-06 CVE-2024-10941 Unspecified vulnerability in Mozilla Firefox
A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash.
network
low complexity
mozilla
6.5
2024-11-06 CVE-2024-10318 Session Fixation vulnerability in F5 products
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time.
network
low complexity
f5 CWE-384
5.4
2024-11-06 CVE-2024-10826 Use After Free vulnerability in Google Chrome
Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2024-11-06 CVE-2024-10827 Use After Free vulnerability in Google Chrome
Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2024-11-06 CVE-2024-20525 Cross-site Scripting vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input.
network
low complexity
cisco CWE-79
6.1
2024-11-06 CVE-2024-20530 Cross-site Scripting vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input.
network
low complexity
cisco CWE-79
6.1
2024-11-06 CVE-2024-20531 Server-Side Request Forgery (SSRF) vulnerability in Cisco Identity Services Engine
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device.
network
low complexity
cisco CWE-918
6.5
2024-11-06 CVE-2024-20537 Incorrect Authorization vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to a lack of server-side validation of Administrator permissions.
network
low complexity
cisco CWE-863
6.5
2024-11-06 CVE-2024-20538 Cross-site Scripting vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input.
network
low complexity
cisco CWE-79
6.1