Show filters
10,544 Total Results
Displaying 311-320 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-11178

Disclosure Date: December 06, 2024 (last updated February 27, 2025)
The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. This is due to the plugin generating too weak OTP, and there’s no attempt or time limit. This makes it possible for unauthenticated attackers to generate and brute force the 6-digit numeric OTP that makes it possible to log in as any existing user on the site, such as an administrator, if they have access to the email.
0
Attacker Value
Unknown

CVE-2024-11149

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.
0
Attacker Value
Unknown

CVE-2024-30962

Disclosure Date: December 05, 2024 (last updated February 27, 2025)
Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process
Attacker Value
Unknown

CVE-2024-30961

Disclosure Date: December 05, 2024 (last updated February 27, 2025)
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in nav2_bt_navigator.
Attacker Value
Unknown

CVE-2024-11148

Disclosure Date: December 05, 2024 (last updated February 27, 2025)
In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.
0
Attacker Value
Unknown

CVE-2024-10933

Disclosure Date: December 05, 2024 (last updated February 27, 2025)
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.
0
Attacker Value
Unknown

CVE-2024-52270

Disclosure Date: December 05, 2024 (last updated February 27, 2025)
User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects DropBox Sign(HelloSign): through 2024-12-04.
0
Attacker Value
Unknown

CVE-2024-8894

Disclosure Date: December 04, 2024 (last updated February 27, 2025)
Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution.
0
Attacker Value
Unknown

CVE-2024-9978

Disclosure Date: December 03, 2024 (last updated February 27, 2025)
in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
Attacker Value
Unknown

CVE-2024-12082

Disclosure Date: December 03, 2024 (last updated February 27, 2025)
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.