Show filters
145 Total Results
Displaying 21-30 of 145
Sort by:
Attacker Value
Unknown

CVE-2025-24500

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
The vulnerability allows an unauthenticated attacker to access information in PAM database.
0
Attacker Value
Unknown

CVE-2024-25566

Disclosure Date: October 29, 2024 (last updated November 09, 2024)
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2023-50304

Disclosure Date: July 18, 2024 (last updated October 19, 2024)
IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 273335.
Attacker Value
Unknown

CVE-2024-38496

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.
0
Attacker Value
Unknown

CVE-2024-38495

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.
0
Attacker Value
Unknown

CVE-2024-38494

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
0
Attacker Value
Unknown

CVE-2024-38493

Disclosure Date: July 15, 2024 (last updated September 11, 2024)
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
Attacker Value
Unknown

CVE-2024-38492

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
0
Attacker Value
Unknown

CVE-2024-38491

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.
0