Show filters
247 Total Results
Displaying 21-30 of 247
Sort by:
Attacker Value
Unknown

CVE-2024-7438

Disclosure Date: August 03, 2024 (last updated September 12, 2024)
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-7437

Disclosure Date: August 03, 2024 (last updated September 12, 2024)
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component Delete User Handler. The manipulation of the argument aid leads to improper control of resource identifiers. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-37325

Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-21093

Disclosure Date: April 16, 2024 (last updated December 21, 2024)
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java VM accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
Attacker Value
Unknown

CVE-2024-27121

Disclosure Date: March 12, 2024 (last updated April 01, 2024)
Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section.
0
Attacker Value
Unknown

CVE-2024-22426

Disclosure Date: February 16, 2024 (last updated January 24, 2025)
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context of the root user, resulting in a complete system compromise.
Attacker Value
Unknown

CVE-2024-22425

Disclosure Date: February 16, 2024 (last updated January 24, 2025)
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint login form. This allows attackers to brute-force the password of valid users in an automated manner.
Attacker Value
Unknown

CVE-2024-21329

Disclosure Date: February 13, 2024 (last updated January 12, 2025)
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2023-6900

Disclosure Date: December 17, 2023 (last updated December 21, 2023)
A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-248258 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-6899

Disclosure Date: December 17, 2023 (last updated December 21, 2023)
A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of the file /settings/save_config of the component Config Handler. The manipulation of the argument value_template leads to code injection. The exploit has been disclosed to the public and may be used. The identifier VDB-248257 was assigned to this vulnerability.