Show filters
393 Total Results
Displaying 41-50 of 393
Sort by:
Attacker Value
Unknown
CVE-2024-7107
Disclosure Date: September 26, 2024 (last updated February 26, 2025)
Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.This issue affects CyberMath: before CYBM.240816253.
0
Attacker Value
Unknown
CVE-2024-6517
Disclosure Date: September 26, 2024 (last updated February 26, 2025)
The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users.
0
Attacker Value
Unknown
CVE-2024-45296
Disclosure Date: September 09, 2024 (last updated February 26, 2025)
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.
0
Attacker Value
Unknown
CVE-2024-37136
Disclosure Date: September 03, 2024 (last updated February 26, 2025)
Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information exposure.
0
Attacker Value
Unknown
CVE-2024-21766
Disclosure Date: August 14, 2024 (last updated February 26, 2025)
Uncontrolled search path for some Intel(R) oneAPI Math Kernel Library software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-21981
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Improper key usage control in AMD Secure Processor
(ASP) may allow an attacker with local access who has gained arbitrary code
execution privilege in ASP to
extract ASP cryptographic keys, potentially resulting in loss of
confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2023-20518
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.
0
Attacker Value
Unknown
CVE-2022-23817
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space, potentially leading to privilege escalation.
0
Attacker Value
Unknown
CVE-2022-23815
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-46772
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
Insufficient input validation in the ABL may allow a privileged
attacker with access to the BIOS menu or UEFI shell to tamper with the
structure headers in SPI ROM causing an out of bounds memory read and write,
potentially resulting in memory corruption or denial of service.
0