Show filters
8,315 Total Results
Displaying 181-190 of 8,315
Sort by:
Attacker Value
Unknown

CVE-2024-12553

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394.
0
Attacker Value
Unknown

CVE-2024-54294

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Authentication Bypass Using an Alternate Path or Channel vulnerability in appgenixinfotech Firebase OTP Authentication allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through 1.0.1.
0
Attacker Value
Unknown

CVE-2024-54266

Disclosure Date: December 13, 2024 (last updated January 13, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.
Attacker Value
Unknown

CVE-2024-54261

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency LLC TAX SERVICE Electronic HDM allows SQL Injection.This issue affects TAX SERVICE Electronic HDM: from n/a through 1.1.2.
0
Attacker Value
Unknown

CVE-2023-41952

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Contact Form - WPManageNinja LLC FluentForm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through 5.0.8.
0
Attacker Value
Unknown

CVE-2023-41873

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in miniOrange SAML SP Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SAML SP Single Sign On: from n/a through 5.0.4.
0
Attacker Value
Unknown

CVE-2023-37987

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in miniOrange YourMembership Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YourMembership Single Sign On: from n/a through 1.1.3.
0
Attacker Value
Unknown

CVE-2023-34381

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2.
0
Attacker Value
Unknown

CVE-2024-50584

Disclosure Date: December 12, 2024 (last updated December 18, 2024)
An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter is vulnerable against blind boolean-based SQL injection attacks. SQL syntax must be injected into the JSON syntax of the templates parameter.
0
Attacker Value
Unknown

CVE-2024-28146

Disclosure Date: December 12, 2024 (last updated December 18, 2024)
The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.
0