Show filters
1,114 Total Results
Displaying 171-180 of 1,114
Sort by:
Attacker Value
Unknown

CVE-2024-6472

Disclosure Date: August 05, 2024 (last updated February 26, 2025)
Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by LibreOffice before the macro is executed. Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway. This issue affects LibreOffice: from 24.2 before 24.2.5.
0
Attacker Value
Unknown

CVE-2024-38890

Disclosure Date: August 02, 2024 (last updated February 26, 2025)
An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.
0
Attacker Value
Unknown

CVE-2024-32865

Disclosure Date: August 01, 2024 (last updated February 26, 2025)
Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.
Attacker Value
Unknown

CVE-2024-41264

Disclosure Date: August 01, 2024 (last updated February 26, 2025)
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
Attacker Value
Unknown

CVE-2024-41256

Disclosure Date: July 31, 2024 (last updated February 26, 2025)
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
Attacker Value
Unknown

CVE-2024-40464

Disclosure Date: July 31, 2024 (last updated February 26, 2025)
An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file
Attacker Value
Unknown

CVE-2024-5249

Disclosure Date: July 30, 2024 (last updated February 26, 2025)
In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
Attacker Value
Unknown

CVE-2023-48396

Disclosure Date: July 30, 2024 (last updated February 26, 2025)
Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a token. This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version 1.0.1, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-27853

Disclosure Date: July 29, 2024 (last updated February 26, 2025)
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
Attacker Value
Unknown

CVE-2024-4786

Disclosure Date: July 26, 2024 (last updated February 26, 2025)
An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on.
0