Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Very High

CVE-2021-3156 "Baron Samedit"

Disclosure Date: January 26, 2021 (last updated January 15, 2025)
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Attacker Value
Very High

CVE-2024-12356

Disclosure Date: December 17, 2024 (last updated February 13, 2025)
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Attacker Value
Unknown

CVE-2024-12686

Disclosure Date: December 18, 2024 (last updated January 15, 2025)
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
Attacker Value
Unknown

CVE-2024-9110

Disclosure Date: October 30, 2024 (last updated February 12, 2025)
A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.
Attacker Value
Unknown

CVE-2024-5813

Disclosure Date: June 11, 2024 (last updated February 12, 2025)
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
Attacker Value
Unknown

CVE-2024-5812

Disclosure Date: June 11, 2024 (last updated February 12, 2025)
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
Attacker Value
Unknown

CVE-2024-4220

Disclosure Date: June 04, 2024 (last updated June 12, 2024)
Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.
Attacker Value
Unknown

CVE-2024-4219

Disclosure Date: June 04, 2024 (last updated June 12, 2024)
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.
Attacker Value
Unknown

CVE-2024-4018

Disclosure Date: April 19, 2024 (last updated April 20, 2024)
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 before 4.0.3.
0
Attacker Value
Unknown

CVE-2024-4017

Disclosure Date: April 19, 2024 (last updated April 20, 2024)
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0.3.
0