Show filters
590 Total Results
Displaying 11-20 of 590
Sort by:
Attacker Value
Unknown
CVE-2024-12078
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
0
Attacker Value
Unknown
CVE-2024-11147
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.
0
Attacker Value
Unknown
CVE-2024-52325
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
0
Attacker Value
Unknown
CVE-2024-51457
Disclosure Date: January 22, 2025 (last updated February 19, 2025)
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2024-49824
Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18
could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.
0
Attacker Value
Unknown
CVE-2024-51448
Disclosure Date: January 18, 2025 (last updated January 19, 2025)
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.
0
Attacker Value
Unknown
CVE-2025-23862
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Missing Authorization vulnerability in SzMake Contact Form 7 Anti Spambot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form 7 Anti Spambot: from n/a through 1.0.1.
0
Attacker Value
Unknown
CVE-2025-0460
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-51456
Disclosure Date: January 12, 2025 (last updated January 13, 2025)
IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.
0
Attacker Value
Unknown
CVE-2024-13289
Disclosure Date: January 09, 2025 (last updated January 10, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot + GTM allows Cross-Site Scripting (XSS).This issue affects Cookiebot + GTM: from 0.0.0 before 1.0.18.
0