Show filters
1,426 Total Results
Displaying 21-30 of 1,426
Sort by:
Attacker Value
Unknown

CVE-2025-25205

Disclosure Date: February 12, 2025 (last updated February 13, 2025)
Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Attackers can craft URLs containing substrings like "/api/items/1/cover" in a query parameter (?r=/api/items/1/cover) to partially bypass authentication or trigger server crashes under certain routes. This could lead to information disclosure of otherwise protected data and, in some cases, a complete denial of service (server crash) if downstream code expects an authenticated user object. Version 2.19.1 contains a patch for the issue.
0
Attacker Value
Unknown

CVE-2025-24042

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2025-24039

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Visual Studio Code Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2025-21206

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Visual Studio Installer Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2022-26389

Disclosure Date: February 07, 2025 (last updated February 08, 2025)
An improper access control vulnerability may allow privilege escalation.This issue affects:  * ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior;  * ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior;  * ELI 250c/BUR 250c Resting Electrocardiograph: Versions 2.1.2 and prior;  * ELI 150c/BUR 150c/MLBUR 150c Resting Electrocardiograph: Versions 2.2.0 and prior.
0
Attacker Value
Unknown

CVE-2022-26388

Disclosure Date: February 07, 2025 (last updated February 08, 2025)
A use of hard-coded password vulnerability may allow authentication abuse.This issue affects ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior; ELI 250c/BUR 250c Resting Electrocardiograph: Versions 2.1.2 and prior; ELI 150c/BUR 150c/MLBUR 150c Resting Electrocardiograph: Versions 2.2.0 and prior.
0
Attacker Value
Unknown

CVE-2025-0675

Disclosure Date: February 07, 2025 (last updated February 07, 2025)
Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclosure.
0
Attacker Value
Unknown

CVE-2025-0674

Disclosure Date: February 07, 2025 (last updated February 07, 2025)
Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user's password within the system. This grants them unauthorized administrative access to protected areas of the application, compromising the device's system security.
0
Attacker Value
Unknown

CVE-2024-49834

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while power-up or power-down sequence of the camera sensor.
Attacker Value
Unknown

CVE-2025-23561

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MLL Audio Player MP3 Ajax allows Stored XSS. This issue affects MLL Audio Player MP3 Ajax: from n/a through 0.7.
0