Show filters
213 Total Results
Displaying 31-40 of 213
Sort by:
Attacker Value
Unknown
CVE-2024-9999
Disclosure Date: November 12, 2024 (last updated November 13, 2024)
In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
0
Attacker Value
Unknown
CVE-2024-9825
Disclosure Date: October 28, 2024 (last updated October 29, 2024)
The Chef Habitat builder-api on-prem-builder package with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect object reference (IDOR) by un-authorized deletion of personal token. Habitat builder consumes builder-api habitat package as a dependency and the vulnerability was specifically due to builder-api habitat package.
The fix was made available in habitat/builder-api/10315/20240913162802 and all the subsequent versions after that. We would recommend user to always use on-prem stable channel.
0
Attacker Value
Unknown
CVE-2024-7763
Disclosure Date: October 24, 2024 (last updated October 31, 2024)
In WhatsUp Gold versions released before 2024.0.0,
an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.
0
Attacker Value
Unknown
CVE-2024-8755
Disclosure Date: October 11, 2024 (last updated November 16, 2024)
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:
Product
Affected Versions
LoadMaster
From 7.2.55.0 to 7.2.60.1 (inclusive)
From 7.2.49.0 to 7.2.54.12 (inclusive)
7.2.48.12 and all prior versions
Multi-Tenant Hypervisor
7.1.35.12 and all prior versions
ECS
All prior versions to 7.2.60.1 (inclusive)
0
Attacker Value
Unknown
CVE-2024-8048
Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
0
Attacker Value
Unknown
CVE-2024-8015
Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
0
Attacker Value
Unknown
CVE-2024-8014
Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
0
Attacker Value
Unknown
CVE-2024-7840
Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
0
Attacker Value
Unknown
CVE-2024-7294
Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
0
Attacker Value
Unknown
CVE-2024-7293
Disclosure Date: October 09, 2024 (last updated October 16, 2024)
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
0