Show filters
5,938 Total Results
Displaying 311-320 of 5,938
Sort by:
Attacker Value
Unknown
CVE-2024-9466
Disclosure Date: October 09, 2024 (last updated February 26, 2025)
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.
0
Attacker Value
Unknown
CVE-2024-9465
Disclosure Date: October 09, 2024 (last updated February 26, 2025)
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
0
Attacker Value
Unknown
CVE-2024-9463
Disclosure Date: October 09, 2024 (last updated February 26, 2025)
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
0
Attacker Value
Unknown
CVE-2024-9622
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts, which may impact systems using load balancers and expose them to risk.
0
Attacker Value
Unknown
CVE-2024-9005
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be
remotely executed on the server when unsafely deserialized data is posted to the web server.
0
Attacker Value
Unknown
CVE-2024-3506
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict conditions.
0
Attacker Value
Unknown
CVE-2024-45153
Disclosure Date: October 07, 2024 (last updated February 26, 2025)
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
0
Attacker Value
Unknown
CVE-2024-33065
Disclosure Date: October 07, 2024 (last updated February 26, 2025)
Memory corruption while taking snapshot when an offset variable is set by camera driver.
0
Attacker Value
Unknown
CVE-2024-23369
Disclosure Date: October 07, 2024 (last updated February 26, 2025)
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
0
Attacker Value
Unknown
CVE-2024-47338
Disclosure Date: October 06, 2024 (last updated February 26, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExpertsio WPExperts Square For GiveWP allows SQL Injection.This issue affects WPExperts Square For GiveWP: from n/a through 1.3.
0