Show filters
83 Total Results
Displaying 11-20 of 83
Sort by:
Attacker Value
Unknown
CVE-2024-55542
Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895.
0
Attacker Value
Unknown
CVE-2024-55541
Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
0
Attacker Value
Unknown
CVE-2024-55540
Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
0
Attacker Value
Unknown
CVE-2024-55538
Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736.
0
Attacker Value
Unknown
CVE-2024-49385
Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736.
0
Attacker Value
Unknown
CVE-2024-55539
Disclosure Date: December 23, 2024 (last updated February 27, 2025)
Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185.
0
Attacker Value
Unknown
CVE-2024-34015
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892.
0
Attacker Value
Unknown
CVE-2024-34014
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.6.599, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.2.181.
0
Attacker Value
Unknown
CVE-2024-43154
Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in BracketSpace Advanced Cron Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.9.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0