Show filters
6,928 Total Results
Displaying 151-160 of 6,928
Sort by:
Attacker Value
Unknown
CVE-2024-21245
Disclosure Date: January 21, 2025 (last updated January 24, 2025)
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
0
Attacker Value
Unknown
CVE-2025-0430
Disclosure Date: January 17, 2025 (last updated January 18, 2025)
Belledonne Communications Linphone-Desktop
is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2025-23559
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Stepan Stepasyuk MemeOne allows Stored XSS.This issue affects MemeOne: from n/a through 2.0.5.
0
Attacker Value
Unknown
CVE-2024-54535
Disclosure Date: January 15, 2025 (last updated January 17, 2025)
A path handling issue was addressed with improved logic. This issue is fixed in watchOS 11.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1. An attacker with access to calendar data could also read reminders.
0
Attacker Value
Unknown
CVE-2025-21402
Disclosure Date: January 14, 2025 (last updated January 28, 2025)
Microsoft Office OneNote Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2025-20620
Disclosure Date: January 14, 2025 (last updated January 14, 2025)
SQL Injection vulnerability exists in STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the affected product may obtain the administrative password of the web management page.
0
Attacker Value
Unknown
CVE-2025-20055
Disclosure Date: January 14, 2025 (last updated January 14, 2025)
OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the affected product may execute an arbitrary OS command.
0
Attacker Value
Unknown
CVE-2025-20016
Disclosure Date: January 14, 2025 (last updated January 14, 2025)
OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an administrative privilege who logged in to the web management page of the affected product may execute an arbitrary OS command.
0
Attacker Value
Unknown
CVE-2024-13271
Disclosure Date: January 09, 2025 (last updated January 10, 2025)
Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.
0
Attacker Value
Unknown
CVE-2024-47239
Disclosure Date: January 08, 2025 (last updated February 05, 2025)
Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.
0