Show filters
508 Total Results
Displaying 21-30 of 508
Sort by:
Attacker Value
Unknown

CVE-2023-23716

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Zendesk Zendesk Support for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zendesk Support for WordPress: from n/a through 1.8.4.
0
Attacker Value
Unknown

CVE-2024-4311

Disclosure Date: November 14, 2024 (last updated November 15, 2024)
zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the current password in the 'Update Password' function, allowing them to take over the user's account. This vulnerability is due to the absence of rate-limiting on the '/api/v1/current-user' endpoint, which does not restrict the number of attempts an attacker can make to guess the current password. Successful exploitation results in the attacker being able to change the password and take control of the account.
0
Attacker Value
Unknown

CVE-2024-21976

Disclosure Date: November 12, 2024 (last updated November 13, 2024)
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
0
Attacker Value
Unknown

CVE-2024-21975

Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2024-21974

Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2024-21949

Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.
Attacker Value
Unknown

CVE-2024-21946

Disclosure Date: November 12, 2024 (last updated December 19, 2024)
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
Attacker Value
Unknown

CVE-2024-21945

Disclosure Date: November 12, 2024 (last updated December 19, 2024)
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
Attacker Value
Unknown

CVE-2024-9129

Disclosure Date: October 22, 2024 (last updated October 23, 2024)
In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Marino
0
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.