Show filters
5,935 Total Results
Displaying 141-150 of 5,935
Sort by:
Attacker Value
Unknown
CVE-2024-45542
Disclosure Date: January 06, 2025 (last updated January 14, 2025)
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
0
Attacker Value
Unknown
CVE-2024-45541
Disclosure Date: January 06, 2025 (last updated January 14, 2025)
Memory corruption when IOCTL call is invoked from user-space to read board data.
0
Attacker Value
Unknown
CVE-2024-12311
Disclosure Date: January 06, 2025 (last updated January 07, 2025)
The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
0
Attacker Value
Unknown
CVE-2024-8447
Disclosure Date: January 02, 2025 (last updated January 05, 2025)
A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.
0
Attacker Value
Unknown
CVE-2024-12405
Disclosure Date: December 24, 2024 (last updated January 05, 2025)
The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-12569
Disclosure Date: December 19, 2024 (last updated January 13, 2025)
Disclosure
of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera
credentials stored in the Recording Server under specific conditions.
0
Attacker Value
Unknown
CVE-2024-12741
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress 5.1 and prior versions. Please note that DAQExpress is an EOL product and will not receive any updates.
0
Attacker Value
Unknown
CVE-2024-10973
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.
0
Attacker Value
Unknown
CVE-2023-37940
Disclosure Date: December 17, 2024 (last updated January 29, 2025)
Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a service access policy's `Service Class` text field.
0
Attacker Value
Unknown
CVE-2024-11993
Disclosure Date: December 17, 2024 (last updated January 29, 2025)
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
0