Show filters
213 Total Results
Displaying 31-40 of 213
Sort by:
Attacker Value
Unknown

CVE-2024-9999

Disclosure Date: November 12, 2024 (last updated November 13, 2024)
In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
0
Attacker Value
Unknown

CVE-2024-9825

Disclosure Date: October 28, 2024 (last updated October 29, 2024)
The Chef Habitat builder-api on-prem-builder package  with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect object reference (IDOR) by un-authorized deletion of personal token.  Habitat builder consumes builder-api habitat package as a dependency and the vulnerability was specifically due to builder-api habitat package. The fix was made available in habitat/builder-api/10315/20240913162802 and all the subsequent versions after that. We would recommend user to always use on-prem stable channel.
0
Attacker Value
Unknown

CVE-2024-7763

Disclosure Date: October 24, 2024 (last updated October 31, 2024)
In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.
Attacker Value
Unknown

CVE-2024-8755

Disclosure Date: October 11, 2024 (last updated November 16, 2024)
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive)
0
Attacker Value
Unknown

CVE-2024-8048

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
Attacker Value
Unknown

CVE-2024-8015

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
Attacker Value
Unknown

CVE-2024-8014

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
Attacker Value
Unknown

CVE-2024-7840

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Attacker Value
Unknown

CVE-2024-7294

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
Attacker Value
Unknown

CVE-2024-7293

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.