Show filters
11,866 Total Results
Displaying 161-170 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-57602

Disclosure Date: February 12, 2025 (last updated February 25, 2025)
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
Attacker Value
Unknown

CVE-2024-13365

Disclosure Date: February 12, 2025 (last updated February 26, 2025)
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown

CVE-2024-13421

Disclosure Date: February 12, 2025 (last updated February 25, 2025)
The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.
Attacker Value
Unknown

CVE-2025-1052

Disclosure Date: February 11, 2025 (last updated February 27, 2025)
Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mintty. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of sixel images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-23382.
Attacker Value
Unknown

CVE-2025-22467

Disclosure Date: February 11, 2025 (last updated February 27, 2025)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.
Attacker Value
Unknown

CVE-2024-47908

Disclosure Date: February 11, 2025 (last updated February 27, 2025)
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Attacker Value
Unknown

CVE-2024-13843

Disclosure Date: February 11, 2025 (last updated February 27, 2025)
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
Attacker Value
Unknown

CVE-2024-13842

Disclosure Date: February 11, 2025 (last updated February 27, 2025)
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
Attacker Value
Unknown

CVE-2024-13830

Disclosure Date: February 11, 2025 (last updated February 27, 2025)
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
Attacker Value
Unknown

CVE-2024-13813

Disclosure Date: February 11, 2025 (last updated February 27, 2025)
Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.