Show filters
3,123 Total Results
Displaying 141-150 of 3,123
Sort by:
Attacker Value
Unknown
CVE-2024-22013
Disclosure Date: September 16, 2024 (last updated September 17, 2024)
U-Boot environment is read from unauthenticated partition.
0
Attacker Value
Unknown
CVE-2024-7888
Disclosure Date: September 13, 2024 (last updated February 26, 2025)
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to, and including, 3.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify forms and various other settings.
0
Attacker Value
Unknown
CVE-2024-20381
Disclosure Date: September 11, 2024 (last updated February 26, 2025)
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device.
This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications to the configuration of the affected application or device, including creating new user accounts or elevating their own privileges on an affected system.
0
Attacker Value
Unknown
CVE-2024-38225
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-45281
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL related tasks. This could result in a high impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2024-44113
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.
0
Attacker Value
Unknown
CVE-2024-7795
Disclosure Date: August 21, 2024 (last updated February 26, 2025)
Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 EV chargers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of the AppAuthenExchangeRandomNum BLE command. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23384.
0
Attacker Value
Unknown
CVE-2024-32928
Disclosure Date: August 19, 2024 (last updated August 21, 2024)
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
0
Attacker Value
Unknown
CVE-2024-42375
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
SAP BusinessObjects Business Intelligence
Platform allows an authenticated attacker to upload malicious code over the
network, that could be executed by the application. On successful exploitation,
the attacker can cause a low impact on the Integrity of the application.
0
Attacker Value
Unknown
CVE-2024-41731
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
SAP BusinessObjects Business Intelligence
Platform allows an authenticated attacker to upload malicious code over the
network, that could be executed by the application. On successful exploitation,
the attacker can cause a low impact on the Integrity of the application.
0