Show filters
424 Total Results
Displaying 231-240 of 424
Sort by:
Attacker Value
Unknown
CVE-2024-25728
Disclosure Date: February 11, 2024 (last updated February 26, 2025)
ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain sensitive information about websites visited by VPN users.
0
Attacker Value
Unknown
CVE-2023-50298
Disclosure Date: February 09, 2024 (last updated February 26, 2025)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.
Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter.
When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides.
An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information,
then send a streaming expression using the mock server's address in "zkHost".
Streaming Expressions are exposed via the "/streaming" handler, with "read" permissions.
Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue.
From these versions on, only zkHost values that have the same server address (regardless of chroot), will use the given ZooKeeper credentials and ACLs when connecting.
0
Attacker Value
Unknown
CVE-2024-22773
Disclosure Date: February 06, 2024 (last updated February 26, 2025)
Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.
0
Attacker Value
Unknown
CVE-2024-22193
Disclosure Date: January 30, 2024 (last updated February 26, 2025)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database. Users should ensure they set the encryption setting correctly. This vulnerability is patched in 4.2.0.
0
Attacker Value
Unknown
CVE-2023-42429
Disclosure Date: January 19, 2024 (last updated February 26, 2025)
Improper buffer restrictions in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-28722
Disclosure Date: January 19, 2024 (last updated February 26, 2025)
Improper buffer restrictions for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-49515
Disclosure Date: January 17, 2024 (last updated February 26, 2025)
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.
0
Attacker Value
Unknown
CVE-2023-37521
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.
0
Attacker Value
Unknown
CVE-2023-5879
Disclosure Date: January 03, 2024 (last updated February 25, 2025)
Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.
0
Attacker Value
Unknown
CVE-2023-23437
Disclosure Date: December 29, 2023 (last updated February 25, 2025)
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak
0