Show filters
1,462 Total Results
Displaying 131-140 of 1,462
Sort by:
Attacker Value
Unknown

CVE-2024-6975

Disclosure Date: July 31, 2024 (last updated February 26, 2025)
Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.
Attacker Value
Unknown

CVE-2024-6974

Disclosure Date: July 31, 2024 (last updated February 26, 2025)
Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.
Attacker Value
Unknown

CVE-2024-6973

Disclosure Date: July 31, 2024 (last updated February 26, 2025)
Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.
Attacker Value
Unknown

CVE-2024-41726

Disclosure Date: July 29, 2024 (last updated February 26, 2025)
Path traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable file may be executed by a user who can log in to the PC where the product's Windows client is installed.
0
Attacker Value
Unknown

CVE-2024-41143

Disclosure Date: July 29, 2024 (last updated February 26, 2025)
Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.
Attacker Value
Unknown

CVE-2024-41139

Disclosure Date: July 29, 2024 (last updated February 26, 2025)
Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a specially crafted DLL file in a specific folder, arbitrary code may be executed with SYSTEM privilege.
0
Attacker Value
Unknown

CVE-2024-6447

Disclosure Date: July 11, 2024 (last updated January 05, 2025)
The FULL – Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in all versions up to, and including, 3.1.12 due to insufficient input sanitization and output escaping as well as missing authorization and capability checks on the related functions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrative user accesses wp-admin dashboard
0
Attacker Value
Unknown

CVE-2024-39569

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an administrative remote attacker running a corresponding SINEMA Remote Connect Server to execute arbitrary code with system privileges on the client system.
Attacker Value
Unknown

CVE-2024-39568

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading proxy configurations. This could allow an authenticated local attacker to execute arbitrary code with system privileges.
Attacker Value
Unknown

CVE-2024-39567

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an authenticated local attacker to execute arbitrary code with system privileges.
0