Show filters
9,277 Total Results
Displaying 161-170 of 9,277
Sort by:
Attacker Value
Unknown

CVE-2025-24865

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
0
Attacker Value
Unknown

CVE-2025-23411

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.
0
Attacker Value
Unknown

CVE-2025-22896

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2024-13182

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator.
Attacker Value
Unknown

CVE-2024-13374

Disclosure Date: February 12, 2025 (last updated February 25, 2025)
The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary file names and directories.
Attacker Value
Unknown

CVE-2025-21322

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Microsoft PC Manager Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-40584

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiAnalyzer BigData version 7.4.0, 7.2.0 through 7.2.7, 7.0.1 through 7.0.6, 6.4.5 through 6.4.7 and 6.2.5, Fortinet FortiAnalyzer Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 and Fortinet FortiManager Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 GUI allows an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTPS or HTTP requests.
0
Attacker Value
Unknown

CVE-2024-36508

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
0
Attacker Value
Unknown

CVE-2024-33504

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.
0
Attacker Value
Unknown

CVE-2023-40721

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
A use of externally-controlled format string vulnerability [CWE-134] in Fortinet FortiOS version 7.4.0 through 7.4.1 and before 7.2.6, FortiProxy version 7.4.0 and before 7.2.7, FortiPAM version 1.1.2 and before 1.0.3, FortiSwitchManager version 7.2.0 through 7.2.2 and before 7.0.2 allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
0