Show filters
2,285 Total Results
Displaying 31-40 of 2,285
Sort by:
Attacker Value
Unknown
CVE-2025-1960
Disclosure Date: March 12, 2025 (last updated March 13, 2025)
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an
attacker to execute unauthorized commands when a system’s default password credentials have not been
changed on first use. The default username is not displayed correctly in the WebHMI interface.
0
Attacker Value
Unknown
CVE-2025-0813
Disclosure Date: March 12, 2025 (last updated March 13, 2025)
CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an
unauthorized user without permission rights has physical access to the EPAS-UI computer and is able to
reboot the workstation and interrupt the normal boot process.
0
Attacker Value
Unknown
CVE-2024-13838
Disclosure Date: March 12, 2025 (last updated March 12, 2025)
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
0
Attacker Value
Unknown
CVE-2025-23368
Disclosure Date: March 04, 2025 (last updated March 05, 2025)
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
0
Attacker Value
Unknown
CVE-2025-1801
Disclosure Date: March 03, 2025 (last updated March 04, 2025)
A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged user, enabling the server to be jeopardized. A user session or confidential data might be vulnerable.
0
Attacker Value
Unknown
CVE-2024-8262
Disclosure Date: March 03, 2025 (last updated March 10, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927.
0
Attacker Value
Unknown
CVE-2024-8261
Disclosure Date: March 03, 2025 (last updated March 10, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OBS: before 24.0927.
0
Attacker Value
Unknown
CVE-2024-54179
Disclosure Date: March 03, 2025 (last updated March 04, 2025)
IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2025-27306
Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pathomation Pathomation allows Stored XSS. This issue affects Pathomation: from n/a through 2.5.1.
0
Attacker Value
Unknown
CVE-2025-22631
Disclosure Date: February 23, 2025 (last updated February 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vbout Marketing Automation allows Reflected XSS. This issue affects Marketing Automation: from n/a through 1.2.6.8.
0