Show filters
1,114 Total Results
Displaying 131-140 of 1,114
Sort by:
Attacker Value
Unknown
CVE-2024-46957
Disclosure Date: September 25, 2024 (last updated February 26, 2025)
Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.
0
Attacker Value
Unknown
CVE-2024-38324
Disclosure Date: September 25, 2024 (last updated February 26, 2025)
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.
0
Attacker Value
Unknown
CVE-2024-43201
Disclosure Date: September 23, 2024 (last updated February 26, 2025)
The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024-07-25) fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information.
0
Attacker Value
Unknown
CVE-2024-39341
Disclosure Date: September 23, 2024 (last updated February 26, 2025)
Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml) after the installation process. This file can be accessed without authentication on HTTP port 80 by guessing the correct IIS webroot path. It includes system configuration parameter names and values with sensitive configuration values encrypted.
0
Attacker Value
Unknown
CVE-2024-45453
Disclosure Date: September 23, 2024 (last updated February 26, 2025)
Authentication Bypass by Spoofing vulnerability in Peter Hardy-vanDoorn Maintenance Redirect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maintenance Redirect: from n/a through 2.0.1.
0
Attacker Value
Unknown
CVE-2023-30464
Disclosure Date: September 18, 2024 (last updated February 26, 2025)
CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.
0
Attacker Value
Unknown
CVE-2024-8287
Disclosure Date: September 18, 2024 (last updated February 26, 2025)
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
0
Attacker Value
Unknown
CVE-2024-39081
Disclosure Date: September 18, 2024 (last updated February 26, 2025)
An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications.
0
Attacker Value
Unknown
CVE-2024-43099
Disclosure Date: September 13, 2024 (last updated February 26, 2025)
The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to maintain security. However, if an attacker captures this session key, they can inject traffic into an ongoing authenticated session. To successfully achieve this, the attacker also needs to spoof both the IP address and MAC address of the originating host which is typical of a session-based attack.
0
Attacker Value
Unknown
CVE-2024-6678
Disclosure Date: September 12, 2024 (last updated February 26, 2025)
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.
0