Show filters
2,455 Total Results
Displaying 21-30 of 2,455
Sort by:
Attacker Value
Unknown

CVE-2020-8300

Disclosure Date: June 16, 2021 (last updated November 28, 2024)
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.
Attacker Value
Unknown

CVE-2020-8273

Disclosure Date: November 16, 2020 (last updated November 28, 2024)
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.
Attacker Value
Very Low

CVE-2020-9340

Disclosure Date: February 22, 2020 (last updated February 21, 2025)
fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter.
Attacker Value
High

CVE-2019-19452

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
A buffer overflow was found in Patriot Viper RGB through 1.1 when processing IoControlCode 0x80102040. Local attackers (including low integrity processes) can exploit this to gain NT AUTHORITY\SYSTEM privileges.
Attacker Value
Moderate

CVE-2019-17387

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.
Attacker Value
High

CVE-2019-17388

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.
Attacker Value
Unknown

CVE-2025-1223

Disclosure Date: February 20, 2025 (last updated February 20, 2025)
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
0
Attacker Value
Unknown

CVE-2025-1222

Disclosure Date: February 20, 2025 (last updated February 20, 2025)
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
0
Attacker Value
Unknown

CVE-2025-1359

Disclosure Date: February 16, 2025 (last updated February 17, 2025)
A vulnerability, which was classified as problematic, has been found in SIAM Industria de Automação e Monitoramento SIAM 2.0. This issue affects some unknown processing of the file /qrcode.jsp. The manipulation of the argument url leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2025-0816

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious IPV6 packets are sent to the device.
0