Show filters
97 Total Results
Displaying 11-20 of 97
Sort by:
Attacker Value
Unknown

CVE-2019-0211

Disclosure Date: April 08, 2019 (last updated July 26, 2024)
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
Attacker Value
Unknown

CVE-2025-0556

Disclosure Date: February 12, 2025 (last updated February 21, 2025)
In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing.
Attacker Value
Unknown

CVE-2024-7295

Disclosure Date: November 13, 2024 (last updated November 19, 2024)
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-8015

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
Attacker Value
Unknown

CVE-2024-7292

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.
Attacker Value
Unknown

CVE-2024-43612

Disclosure Date: October 08, 2024 (last updated October 22, 2024)
Power BI Report Server Spoofing Vulnerability
Attacker Value
Unknown

CVE-2024-43481

Disclosure Date: October 08, 2024 (last updated October 17, 2024)
Power BI Report Server Spoofing Vulnerability
Attacker Value
Unknown

CVE-2024-3325

Disclosure Date: July 10, 2024 (last updated July 11, 2024)
Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.
0
Attacker Value
Unknown

CVE-2024-4837

Disclosure Date: May 15, 2024 (last updated January 17, 2025)
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability.