Show filters
469 Total Results
Displaying 21-30 of 469
Sort by:
Attacker Value
Unknown

CVE-2024-13336

Disclosure Date: February 19, 2025 (last updated March 07, 2025)
The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'disable-auto-updates' page. This makes it possible for unauthenticated attackers to disable all auto updates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2025-23657

Disclosure Date: February 14, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WordPress-to-candidate for Salesforce CRM allows Reflected XSS. This issue affects WordPress-to-candidate for Salesforce CRM: from n/a through 1.0.1.
0
Attacker Value
Unknown

CVE-2024-42492

Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown

CVE-2025-1244

Disclosure Date: February 12, 2025 (last updated March 04, 2025)
A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
0
Attacker Value
Unknown

CVE-2025-24036

Disclosure Date: February 11, 2025 (last updated February 27, 2025)
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2025-22402

Disclosure Date: February 07, 2025 (last updated March 05, 2025)
Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Attacker Value
Unknown

CVE-2025-24355

Disclosure Date: January 24, 2025 (last updated February 27, 2025)
Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pipeline which contains a `maven` source configured with basic auth credentials, the credentials are being leaked in the application execution logs in case of failure. Credentials are properly sanitized when the operation is successful but not when for whatever reason there is a failure in the maven repository, e.g. wrong coordinates provided, not existing artifact or version. Version 0.93.0 contains a patch for the issue.
0
Attacker Value
Unknown

CVE-2024-11218

Disclosure Date: January 22, 2025 (last updated March 05, 2025)
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
0
Attacker Value
Unknown

CVE-2025-21399

Disclosure Date: January 17, 2025 (last updated February 27, 2025)
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2025-21360

Disclosure Date: January 14, 2025 (last updated February 27, 2025)
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability