Show filters
1,114 Total Results
Displaying 161-170 of 1,114
Sort by:
Attacker Value
Unknown
CVE-2024-35538
Disclosure Date: August 19, 2024 (last updated February 26, 2025)
Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.
0
Attacker Value
Unknown
CVE-2023-50314
Disclosure Date: August 14, 2024 (last updated February 26, 2025)
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713.
0
Attacker Value
Unknown
CVE-2023-50315
Disclosure Date: August 14, 2024 (last updated February 26, 2025)
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.
0
Attacker Value
Unknown
CVE-2024-7570
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.
0
Attacker Value
Unknown
CVE-2024-37015
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.
0
Attacker Value
Unknown
CVE-2024-5445
Disclosure Date: August 12, 2024 (last updated February 26, 2025)
Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position.
0
Attacker Value
Unknown
CVE-2024-32765
Disclosure Date: August 12, 2024 (last updated February 26, 2025)
A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 5.1.8.2823 build 20240712 and later
QuTS hero h5.1.8.2823 build 20240712 and later
0
Attacker Value
Unknown
CVE-2024-41432
Disclosure Date: August 07, 2024 (last updated February 26, 2025)
An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP spoofing, attackers can bypass account lockout mechanisms during attempts to log into admin accounts, spoof IP addresses in requests sent to the server, and impersonate IP addresses that have logged into user accounts, etc.
0
Attacker Value
Unknown
CVE-2024-42395
Disclosure Date: August 06, 2024 (last updated February 26, 2025)
There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
0
Attacker Value
Unknown
CVE-2024-7383
Disclosure Date: August 05, 2024 (last updated February 26, 2025)
A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.
0