Show filters
461 Total Results
Displaying 41-50 of 461
Sort by:
Attacker Value
Unknown

CVE-2024-5471

Disclosure Date: July 17, 2024 (last updated July 19, 2024)
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.
Attacker Value
Unknown

CVE-2024-27311

Disclosure Date: July 17, 2024 (last updated July 19, 2024)
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.
Attacker Value
Unknown

CVE-2024-5322

Disclosure Date: July 01, 2024 (last updated July 02, 2024)
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.
0
Attacker Value
Unknown

CVE-2024-28200

Disclosure Date: July 01, 2024 (last updated August 23, 2024)
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.
Attacker Value
Unknown

CVE-2024-35249

Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-35248

Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-31485

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.
0
Attacker Value
Unknown

CVE-2024-31484

Disclosure Date: May 14, 2024 (last updated June 11, 2024)
A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30), CPCX26 Central Processing/Communication (All versions < V06.02), ETA4 Ethernet Interface IEC60870-5-104 (All versions < V10.46), ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2 (All versions < V03.27), PCCX26 Ax 1703 PE, Contr, Communication Element (All versions < V06.05). The affected devices contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.
0
Attacker Value
Unknown

CVE-2024-33612

Disclosure Date: May 08, 2024 (last updated December 21, 2024)
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. A successful exploit of this vulnerability can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2024-32049

Disclosure Date: May 08, 2024 (last updated December 21, 2024)
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.