Show filters
1,114 Total Results
Displaying 171-180 of 1,114
Sort by:
Attacker Value
Unknown
CVE-2024-6472
Disclosure Date: August 05, 2024 (last updated February 26, 2025)
Certificate Validation user interface in LibreOffice allows potential vulnerability.
Signed macros are scripts that have been digitally signed by the
developer using a cryptographic signature. When a document with a signed
macro is opened a warning is displayed by LibreOffice before the macro
is executed.
Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.
This issue affects LibreOffice: from 24.2 before 24.2.5.
0
Attacker Value
Unknown
CVE-2024-38890
Disclosure Date: August 02, 2024 (last updated February 26, 2025)
An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.
0
Attacker Value
Unknown
CVE-2024-32865
Disclosure Date: August 01, 2024 (last updated February 26, 2025)
Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.
0
Attacker Value
Unknown
CVE-2024-41264
Disclosure Date: August 01, 2024 (last updated February 26, 2025)
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
0
Attacker Value
Unknown
CVE-2024-41256
Disclosure Date: July 31, 2024 (last updated February 26, 2025)
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2024-40464
Disclosure Date: July 31, 2024 (last updated February 26, 2025)
An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file
0
Attacker Value
Unknown
CVE-2024-5249
Disclosure Date: July 30, 2024 (last updated February 26, 2025)
In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
0
Attacker Value
Unknown
CVE-2023-48396
Disclosure Date: July 30, 2024 (last updated February 26, 2025)
Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge
any token to log in any user.
Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a token.
This issue affects Apache SeaTunnel: 1.0.0.
Users are recommended to upgrade to version 1.0.1, which fixes the issue.
0
Attacker Value
Unknown
CVE-2024-27853
Disclosure Date: July 29, 2024 (last updated February 26, 2025)
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
0
Attacker Value
Unknown
CVE-2024-4786
Disclosure Date: July 26, 2024 (last updated February 26, 2025)
An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on.
0