Show filters
590 Total Results
Displaying 11-20 of 590
Sort by:
Attacker Value
Unknown

CVE-2024-12078

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
0
Attacker Value
Unknown

CVE-2024-11147

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.
0
Attacker Value
Unknown

CVE-2024-52325

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
0
Attacker Value
Unknown

CVE-2024-51457

Disclosure Date: January 22, 2025 (last updated February 19, 2025)
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown

CVE-2024-49824

Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.
Attacker Value
Unknown

CVE-2024-51448

Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.
Attacker Value
Unknown

CVE-2025-23862

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Missing Authorization vulnerability in SzMake Contact Form 7 Anti Spambot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form 7 Anti Spambot: from n/a through 1.0.1.
0
Attacker Value
Unknown

CVE-2025-0460

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-51456

Disclosure Date: January 12, 2025 (last updated January 13, 2025)
IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.
Attacker Value
Unknown

CVE-2024-13289

Disclosure Date: January 09, 2025 (last updated January 10, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot + GTM allows Cross-Site Scripting (XSS).This issue affects Cookiebot + GTM: from 0.0.0 before 1.0.18.
0