Show filters
259 Total Results
Displaying 11-20 of 259
Sort by:
Attacker Value
Unknown

CVE-2024-6097

Disclosure Date: February 12, 2025 (last updated February 25, 2025)
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.
Attacker Value
Unknown

CVE-2024-8401

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the product.
0
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-47815

Disclosure Date: October 09, 2024 (last updated October 10, 2024)
IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of them require elevated permissions. Some are available to anyone who has the `editincidents` right, some are available to those who can edit interface messages (typically administrators and interface admins), and one is available to those who can edit LocalSettings.php. These issues have been addressed in commit `43896a4` and all users are advised to upgrade. Users unable to upgrade should prevent access to the Special:IncidentReports page.
0
Attacker Value
Unknown

CVE-2024-8048

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
Attacker Value
Unknown

CVE-2024-8014

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
Attacker Value
Unknown

CVE-2024-7840

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Attacker Value
Unknown

CVE-2024-7294

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
Attacker Value
Unknown

CVE-2024-7293

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
Attacker Value
Unknown

CVE-2024-47071

Disclosure Date: October 01, 2024 (last updated October 02, 2024)
OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4.
0