Show filters
410 Total Results
Displaying 21-30 of 410
Sort by:
Attacker Value
Unknown

CVE-2025-23051

Disclosure Date: January 14, 2025 (last updated February 27, 2025)
An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.
0
Attacker Value
Unknown

CVE-2024-54010

Disclosure Date: January 08, 2025 (last updated February 27, 2025)
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.
0
Attacker Value
Unknown

CVE-2024-51737

Disclosure Date: January 08, 2025 (last updated February 27, 2025)
RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a specially crafted LIMIT command argument, or FT.SEARCH with a specially crafted KNN command argument, can trigger an integer overflow, leading to heap overflow and potential remote code execution. This vulnerability is fixed in 2.6.24, 2.8.21, and 2.10.10. Avoid setting value of -1 or large values for configuration parameters MAXSEARCHRESULTS and MAXAGGREGATERESULTS, to avoid exploiting large LIMIT arguments.
0
Attacker Value
Unknown

CVE-2024-54007

Disclosure Date: January 07, 2025 (last updated February 27, 2025)
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.
0
Attacker Value
Unknown

CVE-2024-54006

Disclosure Date: January 07, 2025 (last updated February 27, 2025)
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.
0
Attacker Value
Unknown

CVE-2024-10932

Disclosure Date: January 04, 2025 (last updated February 27, 2025)
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files, retrieve sensitive data, or execute code. An administrator must create a staging site in order to trigger the exploit.
Attacker Value
Unknown

CVE-2024-56218

Disclosure Date: December 31, 2024 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in AuRise Creative, SevenSpark Contact Form 7 Dynamic Text Extension allows Cross Site Request Forgery.This issue affects Contact Form 7 Dynamic Text Extension: from n/a through 5.0.1.
0
Attacker Value
Unknown

CVE-2024-54009

Disclosure Date: December 19, 2024 (last updated February 27, 2025)
Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.
0
Attacker Value
Unknown

CVE-2023-41690

Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Wiser Notify WiserNotify Social Proof allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserNotify Social Proof: from n/a through 2.5.
0
Attacker Value
Unknown

CVE-2023-34009

Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media & Share Icons: from n/a through 2.8.1.
0