Show filters
9,280 Total Results
Displaying 311-320 of 9,280
Sort by:
Attacker Value
Unknown

CVE-2024-49816

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
Attacker Value
Unknown

CVE-2021-26280

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
Locally installed application can bypass the permission check and perform system operations that require permission.
0
Attacker Value
Unknown

CVE-2024-6001

Disclosure Date: December 16, 2024 (last updated February 27, 2025)
An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.
Attacker Value
Unknown

CVE-2024-4762

Disclosure Date: December 16, 2024 (last updated February 27, 2025)
An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.
Attacker Value
Unknown

CVE-2024-55993

Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in PickPlugins Job Board Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through 2.1.60.
0
Attacker Value
Unknown

CVE-2024-55989

Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kyle M. Brown WP Simple Pay Lite Manager allows SQL Injection.This issue affects WP Simple Pay Lite Manager: from n/a through 1.4.
0
Attacker Value
Unknown

CVE-2024-12553

Disclosure Date: December 13, 2024 (last updated February 27, 2025)
GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394.
0
Attacker Value
Unknown

CVE-2024-54295

Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Authentication Bypass Using an Alternate Path or Channel vulnerability in InspireUI ListApp Mobile Manager allows Authentication Bypass.This issue affects ListApp Mobile Manager: from n/a through 1.7.7.
0
Attacker Value
Unknown

CVE-2024-54265

Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Reflected XSS.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.6.
0
Attacker Value
Unknown

CVE-2024-54238

Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Colin Tomele Board Document Manager from CHUHPL allows Reflected XSS.This issue affects Board Document Manager from CHUHPL: from n/a through 1.9.1.
0