Show filters
1,018 Total Results
Displaying 71-80 of 1,018
Sort by:
Attacker Value
Unknown
CVE-2024-32765
Disclosure Date: August 12, 2024 (last updated February 26, 2025)
A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 5.1.8.2823 build 20240712 and later
QuTS hero h5.1.8.2823 build 20240712 and later
0
Attacker Value
Unknown
CVE-2024-41432
Disclosure Date: August 07, 2024 (last updated February 26, 2025)
An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP spoofing, attackers can bypass account lockout mechanisms during attempts to log into admin accounts, spoof IP addresses in requests sent to the server, and impersonate IP addresses that have logged into user accounts, etc.
0
Attacker Value
Unknown
CVE-2024-42395
Disclosure Date: August 06, 2024 (last updated February 26, 2025)
There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
0
Attacker Value
Unknown
CVE-2024-7383
Disclosure Date: August 05, 2024 (last updated February 26, 2025)
A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.
0
Attacker Value
Unknown
CVE-2024-6472
Disclosure Date: August 05, 2024 (last updated February 26, 2025)
Certificate Validation user interface in LibreOffice allows potential vulnerability.
Signed macros are scripts that have been digitally signed by the
developer using a cryptographic signature. When a document with a signed
macro is opened a warning is displayed by LibreOffice before the macro
is executed.
Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.
This issue affects LibreOffice: from 24.2 before 24.2.5.
0
Attacker Value
Unknown
CVE-2024-38890
Disclosure Date: August 02, 2024 (last updated February 26, 2025)
An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.
0
Attacker Value
Unknown
CVE-2024-32865
Disclosure Date: August 01, 2024 (last updated February 26, 2025)
Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.
0
Attacker Value
Unknown
CVE-2024-41264
Disclosure Date: August 01, 2024 (last updated February 26, 2025)
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
0
Attacker Value
Unknown
CVE-2024-41256
Disclosure Date: July 31, 2024 (last updated February 26, 2025)
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2024-40464
Disclosure Date: July 31, 2024 (last updated February 26, 2025)
An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file
0