Show filters
19,892 Total Results
Displaying 291-300 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-49039

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
Windows Task Scheduler Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-21216

Disclosure Date: October 15, 2024 (last updated February 26, 2025)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Attacker Value
Unknown

CVE-2024-9487

Disclosure Date: October 10, 2024 (last updated February 26, 2025)
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted assertions feature to be enabled, and the attacker would require direct network access as well as a signed SAML response or metadata document. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.15 and was fixed in versions 3.11.16, 3.12.10, 3.13.5, and 3.14.2. This vulnerability was reported via the GitHub Bug Bounty program.
Attacker Value
Unknown

CVE-2024-38813

Disclosure Date: September 17, 2024 (last updated February 26, 2025)
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
Attacker Value
Unknown

CVE-2024-38213

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Windows Mark of the Web Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2024-38193

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-38202

Disclosure Date: August 08, 2024 (last updated February 26, 2025)
Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS). However, an attacker attempting to exploit this vulnerability requires additional interaction by a privileged user to be successful. Microsoft has developed a security update to mitigate this threat which was made available October 08, 2024 and is provided in the Security Updates table of this CVE for customers to download. Note: Depending on your version of Windows, additional steps may be required to update Windows Recovery Environment (WinRE) to be protected from this vulnerability. Please refer to the FAQ section for more information. Guidance for customers who cannot immediately implement the update is provided in the Recommended Actions section of this CVE to help reduce the risks associated with this …
Attacker Value
Unknown

CVE-2024-38080

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
Windows Hyper-V Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-37079

Disclosure Date: June 18, 2024 (last updated February 26, 2025)
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Attacker Value
Unknown

CVE-2024-30300

Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability to gain access to sensitive information which may include system or user privileges. Exploitation of this issue does not require user interaction.