Show filters
278 Total Results
Displaying 31-40 of 278
Sort by:
Attacker Value
Unknown
CVE-2024-7421
Disclosure Date: September 25, 2024 (last updated October 02, 2024)
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
0
Attacker Value
Unknown
CVE-2024-6512
Disclosure Date: September 25, 2024 (last updated October 02, 2024)
Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.
0
Attacker Value
Unknown
CVE-2024-8678
Disclosure Date: September 25, 2024 (last updated October 03, 2024)
The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoint in all versions up to, and including, 4.17.3. This makes it possible for unauthenticated attackers to mark orders as completed.
0
Attacker Value
Unknown
CVE-2024-5969
Disclosure Date: July 27, 2024 (last updated January 05, 2025)
The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.
0
Attacker Value
Unknown
CVE-2024-6492
Disclosure Date: July 16, 2024 (last updated July 17, 2024)
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website.
0
Attacker Value
Unknown
CVE-2024-6354
Disclosure Date: June 26, 2024 (last updated June 27, 2024)
Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.
0
Attacker Value
Unknown
CVE-2024-4846
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.
0
Attacker Value
Unknown
CVE-2023-45195
Disclosure Date: June 24, 2024 (last updated June 25, 2024)
Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.
0
Attacker Value
Unknown
CVE-2023-45196
Disclosure Date: June 24, 2024 (last updated June 25, 2024)
Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.
0
Attacker Value
Unknown
CVE-2023-45197
Disclosure Date: June 21, 2024 (last updated June 25, 2024)
The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.3.
0