Show filters
4,200 Total Results
Displaying 121-130 of 4,200
Sort by:
Attacker Value
Unknown
CVE-2024-54000
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when a request to .well-known/assetlinks.json" returns a 302 redirect. This is a bypass of the fix for CVE-2024-29190 and is fixed in 3.9.7.
0
Attacker Value
Unknown
CVE-2024-53999
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users in the application use the "Diff or Compare" functionality, they are affected by a Stored Cross-Site Scripting vulnerability. This vulnerability is fixed in 4.2.9.
0
Attacker Value
Unknown
CVE-2024-38827
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.
0
Attacker Value
Unknown
CVE-2024-49806
Disclosure Date: November 29, 2024 (last updated January 30, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
0
Attacker Value
Unknown
CVE-2024-49805
Disclosure Date: November 29, 2024 (last updated January 30, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
0
Attacker Value
Unknown
CVE-2024-49804
Disclosure Date: November 29, 2024 (last updated January 30, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.
0
Attacker Value
Unknown
CVE-2024-49803
Disclosure Date: November 29, 2024 (last updated January 30, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
0
Attacker Value
Unknown
CVE-2024-11482
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
0
Attacker Value
Unknown
CVE-2024-11481
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.
0
Attacker Value
Unknown
CVE-2024-10570
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 2.145, as well as insufficient input sanitization and validation. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0