Show filters
3,770 Total Results
Displaying 111-120 of 3,770
Sort by:
Attacker Value
Unknown

CVE-2024-49349

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2024-49339

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2025-21415

Disclosure Date: January 29, 2025 (last updated February 08, 2025)
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.
Attacker Value
Unknown

CVE-2025-23385

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible
0
Attacker Value
Unknown

CVE-2025-0754

Disclosure Date: January 28, 2025 (last updated January 28, 2025)
The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log injection and spoofing attacks. Such injections can mislead logging mechanisms, enabling attackers to manipulate log entries or execute reflected cross-site scripting (XSS) attacks.
Attacker Value
Unknown

CVE-2025-0752

Disclosure Date: January 28, 2025 (last updated January 28, 2025)
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.
Attacker Value
Unknown

CVE-2024-38325

Disclosure Date: January 27, 2025 (last updated January 28, 2025)
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Attacker Value
Unknown

CVE-2024-31906

Disclosure Date: January 26, 2025 (last updated January 27, 2025)
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
Attacker Value
Unknown

CVE-2024-52327

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
0
Attacker Value
Unknown

CVE-2025-24403

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials stored in Jenkins.
0