Show filters
977 Total Results
Displaying 121-130 of 977
Sort by:
Attacker Value
Unknown

CVE-2024-22054

Disclosure Date: February 20, 2024 (last updated March 04, 2024)
A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi Access Points to Version 6.6.55 or later. Update UniFi Switches to Version 6.6.61 or later. Update UniFi LTE Backup to Version 6.6.57 or later. Update UniFi Express to Version 3.2.5 or later.
0
Attacker Value
Unknown

CVE-2023-4637

Disclosure Date: February 05, 2024 (last updated February 13, 2024)
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.
Attacker Value
Unknown

CVE-2024-22903

Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
Attacker Value
Unknown

CVE-2024-22902

Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
Attacker Value
Unknown

CVE-2024-22901

Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
Attacker Value
Unknown

CVE-2024-22900

Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
Attacker Value
Unknown

CVE-2024-22899

Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
Attacker Value
Unknown

CVE-2023-6266

Disclosure Date: January 11, 2024 (last updated January 18, 2024)
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to download back-up files which can contain sensitive information such as user passwords, PII, database credentials, and much more.
Attacker Value
Unknown

CVE-2023-6271

Disclosure Date: January 01, 2024 (last updated January 09, 2024)
The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.
Attacker Value
Unknown

CVE-2023-52185

Disclosure Date: December 31, 2023 (last updated January 06, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Everestthemes Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin.This issue affects Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin: from n/a through 2.1.9.