Show filters
347,972 Total Results
Displaying 11-20 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2024-47266
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to read specific files containing non-sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2024-47265
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2024-47264
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to delete arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2024-13346
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
0
Attacker Value
Unknown
CVE-2024-13345
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
0
Attacker Value
Unknown
CVE-2025-1070
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device
inoperable when a malicious file is downloaded.
0
Attacker Value
Unknown
CVE-2025-1060
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure
of data when network traffic is being sniffed by an attacker.
0
Attacker Value
Unknown
CVE-2025-1059
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could
cause communications to stop when malicious packets are sent to the webserver of the device.
0
Attacker Value
Unknown
CVE-2025-1058
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device
inoperable when malicious firmware is downloaded.
0
Attacker Value
Unknown
CVE-2025-0692
Disclosure Date: February 13, 2025 (last updated February 13, 2025)
The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0