Show filters
347,972 Total Results
Displaying 11-20 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-47266

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to read specific files containing non-sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-47265

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-47264

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to delete arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2024-13346

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2024-13345

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2025-1070

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file is downloaded.
0
Attacker Value
Unknown

CVE-2025-1060

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.
0
Attacker Value
Unknown

CVE-2025-1059

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious packets are sent to the webserver of the device.
0
Attacker Value
Unknown

CVE-2025-1058

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is downloaded.
0
Attacker Value
Unknown

CVE-2025-0692

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0