Show filters
9,280 Total Results
Displaying 311-320 of 9,280
Sort by:
Attacker Value
Unknown
CVE-2024-49816
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
0
Attacker Value
Unknown
CVE-2021-26280
Disclosure Date: December 17, 2024 (last updated February 27, 2025)
Locally installed application can bypass the permission check and perform system operations that require permission.
0
Attacker Value
Unknown
CVE-2024-6001
Disclosure Date: December 16, 2024 (last updated February 27, 2025)
An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.
0
Attacker Value
Unknown
CVE-2024-4762
Disclosure Date: December 16, 2024 (last updated February 27, 2025)
An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.
0
Attacker Value
Unknown
CVE-2024-55993
Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in PickPlugins Job Board Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through 2.1.60.
0
Attacker Value
Unknown
CVE-2024-55989
Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kyle M. Brown WP Simple Pay Lite Manager allows SQL Injection.This issue affects WP Simple Pay Lite Manager: from n/a through 1.4.
0
Attacker Value
Unknown
CVE-2024-12553
Disclosure Date: December 13, 2024 (last updated February 27, 2025)
GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used.
The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394.
0
Attacker Value
Unknown
CVE-2024-54295
Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Authentication Bypass Using an Alternate Path or Channel vulnerability in InspireUI ListApp Mobile Manager allows Authentication Bypass.This issue affects ListApp Mobile Manager: from n/a through 1.7.7.
0
Attacker Value
Unknown
CVE-2024-54265
Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Reflected XSS.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.6.
0
Attacker Value
Unknown
CVE-2024-54238
Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Colin Tomele Board Document Manager from CHUHPL allows Reflected XSS.This issue affects Board Document Manager from CHUHPL: from n/a through 1.9.1.
0