Show filters
11,866 Total Results
Displaying 161-170 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2024-57602
Disclosure Date: February 12, 2025 (last updated February 25, 2025)
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
0
Attacker Value
Unknown
CVE-2024-13365
Disclosure Date: February 12, 2025 (last updated February 26, 2025)
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2024-13421
Disclosure Date: February 12, 2025 (last updated February 25, 2025)
The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.
0
Attacker Value
Unknown
CVE-2025-1052
Disclosure Date: February 11, 2025 (last updated February 27, 2025)
Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mintty. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of sixel images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-23382.
0
Attacker Value
Unknown
CVE-2025-22467
Disclosure Date: February 11, 2025 (last updated February 27, 2025)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-47908
Disclosure Date: February 11, 2025 (last updated February 27, 2025)
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-13843
Disclosure Date: February 11, 2025 (last updated February 27, 2025)
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
0
Attacker Value
Unknown
CVE-2024-13842
Disclosure Date: February 11, 2025 (last updated February 27, 2025)
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
0
Attacker Value
Unknown
CVE-2024-13830
Disclosure Date: February 11, 2025 (last updated February 27, 2025)
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
0
Attacker Value
Unknown
CVE-2024-13813
Disclosure Date: February 11, 2025 (last updated February 27, 2025)
Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.
0