Show filters
5,935 Total Results
Displaying 121-130 of 5,935
Sort by:
Attacker Value
Unknown

CVE-2024-11734

Disclosure Date: January 14, 2025 (last updated January 14, 2025)
A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.
Attacker Value
Unknown

CVE-2024-12568

Disclosure Date: January 13, 2025 (last updated January 13, 2025)
The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workflow settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown

CVE-2024-12567

Disclosure Date: January 13, 2025 (last updated January 13, 2025)
The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown

CVE-2024-12566

Disclosure Date: January 13, 2025 (last updated January 13, 2025)
The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown

CVE-2024-11636

Disclosure Date: January 13, 2025 (last updated January 13, 2025)
The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text Block options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown

CVE-2025-0107

Disclosure Date: January 11, 2025 (last updated January 16, 2025)
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
0
Attacker Value
Unknown

CVE-2025-0106

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.
0
Attacker Value
Unknown

CVE-2025-0105

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem.
0
Attacker Value
Unknown

CVE-2025-0104

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition browser-session theft.
0
Attacker Value
Unknown

CVE-2025-0103

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
0