Show filters
6,927 Total Results
Displaying 101-110 of 6,927
Sort by:
Attacker Value
Unknown
CVE-2024-32037
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.
0
Attacker Value
Unknown
CVE-2025-24200
Disclosure Date: February 10, 2025 (last updated February 14, 2025)
An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
0
Attacker Value
Unknown
CVE-2025-25107
Disclosure Date: February 07, 2025 (last updated February 07, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites allows Cross Site Request Forgery. This issue affects OneStore Sites: from n/a through 0.1.1.
0
Attacker Value
Unknown
CVE-2023-5878
Disclosure Date: February 06, 2025 (last updated February 07, 2025)
Honeywell OneWireless
Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to
R322.3, R330.2 or the most recent version of this product2.
0
Attacker Value
Unknown
CVE-2025-22643
Disclosure Date: February 04, 2025 (last updated February 05, 2025)
Missing Authorization vulnerability in FameThemes OnePress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OnePress: from n/a through 2.3.11.
0
Attacker Value
Unknown
CVE-2025-22206
Disclosure Date: February 04, 2025 (last updated February 05, 2025)
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.
0
Attacker Value
Unknown
CVE-2024-13356
Disclosure Date: February 04, 2025 (last updated February 04, 2025)
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unauthenticated attackers to delete admin user accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2025-22205
Disclosure Date: February 04, 2025 (last updated February 04, 2025)
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
0
Attacker Value
Unknown
CVE-2025-22681
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Missing Authorization vulnerability in Xfinity Soft Content Cloner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Content Cloner: from n/a through 1.0.1.
0
Attacker Value
Unknown
CVE-2025-24609
Disclosure Date: January 31, 2025 (last updated January 31, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PortOne PORTONE 우커머스 결제 allows Reflected XSS. This issue affects PORTONE 우커머스 결제: from n/a through 3.2.4.
0