Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
Very High
CVE-2023-26258
Disclosure Date: July 03, 2023 (last updated October 08, 2023)
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.
2
Attacker Value
Very High
CVE-2023-35885
Disclosure Date: June 20, 2023 (last updated October 08, 2023)
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
2
Attacker Value
Unknown
CVE-2024-7596
Disclosure Date: February 05, 2025 (last updated February 07, 2025)
Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
0
Attacker Value
Unknown
CVE-2024-24320
Disclosure Date: June 14, 2024 (last updated August 08, 2024)
Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function.
0
Attacker Value
Unknown
CVE-2024-30247
Disclosure Date: March 29, 2024 (last updated January 05, 2025)
NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be used by anyone with access to NextCloudPi web-panel, no authentication is required. It is recommended that the NextCloudPi is upgraded to 1.53.1.
0
Attacker Value
Unknown
CVE-2024-1917
Disclosure Date: March 15, 2024 (last updated June 14, 2024)
Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.
0
Attacker Value
Unknown
CVE-2024-1916
Disclosure Date: March 15, 2024 (last updated June 14, 2024)
Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.
0
Attacker Value
Unknown
CVE-2024-1915
Disclosure Date: March 15, 2024 (last updated June 14, 2024)
Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.
0
Attacker Value
Unknown
CVE-2024-0803
Disclosure Date: March 15, 2024 (last updated June 14, 2024)
Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.
0
Attacker Value
Unknown
CVE-2024-0802
Disclosure Date: March 15, 2024 (last updated June 14, 2024)
Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from a target product or execute malicious code on a target product by sending a specially crafted packet.
0