Show filters
2,285 Total Results
Displaying 31-40 of 2,285
Sort by:
Attacker Value
Unknown

CVE-2025-1960

Disclosure Date: March 12, 2025 (last updated March 13, 2025)
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized commands when a system’s default password credentials have not been changed on first use. The default username is not displayed correctly in the WebHMI interface.
0
Attacker Value
Unknown

CVE-2025-0813

Disclosure Date: March 12, 2025 (last updated March 13, 2025)
CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permission rights has physical access to the EPAS-UI computer and is able to reboot the workstation and interrupt the normal boot process.
0
Attacker Value
Unknown

CVE-2024-13838

Disclosure Date: March 12, 2025 (last updated March 12, 2025)
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Attacker Value
Unknown

CVE-2025-23368

Disclosure Date: March 04, 2025 (last updated March 05, 2025)
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
Attacker Value
Unknown

CVE-2025-1801

Disclosure Date: March 03, 2025 (last updated March 04, 2025)
A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged user, enabling the server to be jeopardized. A user session or confidential data might be vulnerable.
Attacker Value
Unknown

CVE-2024-8262

Disclosure Date: March 03, 2025 (last updated March 10, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927.
Attacker Value
Unknown

CVE-2024-8261

Disclosure Date: March 03, 2025 (last updated March 10, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OBS: before 24.0927.
Attacker Value
Unknown

CVE-2024-54179

Disclosure Date: March 03, 2025 (last updated March 04, 2025)
IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2025-27306

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pathomation Pathomation allows Stored XSS. This issue affects Pathomation: from n/a through 2.5.1.
0
Attacker Value
Unknown

CVE-2025-22631

Disclosure Date: February 23, 2025 (last updated February 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vbout Marketing Automation allows Reflected XSS. This issue affects Marketing Automation: from n/a through 1.2.6.8.
0