Show filters
145 Total Results
Displaying 1-10 of 145
Sort by:
Attacker Value
Unknown

CVE-2024-13723

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
0
Attacker Value
Unknown

CVE-2024-13722

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
0
Attacker Value
Unknown

CVE-2024-23690

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary OS commands as root over Telnet by sending crafted "util backup_configuration" commands.
0
Attacker Value
Unknown

CVE-2024-13356

Disclosure Date: February 04, 2025 (last updated February 04, 2025)
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unauthenticated attackers to delete admin user accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-10603

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.
0
Attacker Value
Unknown

CVE-2024-10026

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
0
Attacker Value
Unknown

CVE-2025-23866

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EU DSGVO Helper allows Reflected XSS. This issue affects EU DSGVO Helper: from n/a through 1.0.6.1.
0
Attacker Value
Unknown

CVE-2025-22137

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, including sensitive system files, via HTTP POST requests. The issue has been patched in version 1.4.0.
0
Attacker Value
Unknown

CVE-2024-12881

Disclosure Date: December 24, 2024 (last updated January 05, 2025)
The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the eos_plugin_reviews_restore_version() function in all versions up to, and including, 0.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary files leveraging files included locally.
Attacker Value
Unknown

CVE-2024-47093

Disclosure Date: December 19, 2024 (last updated December 20, 2024)
Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS
0