Show filters
1,423 Total Results
Displaying 41-50 of 1,423
Sort by:
Attacker Value
Unknown

CVE-2024-56413

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
0
Attacker Value
Unknown

CVE-2024-55543

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
0
Attacker Value
Unknown

CVE-2024-55542

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895.
0
Attacker Value
Unknown

CVE-2024-55541

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
0
Attacker Value
Unknown

CVE-2024-55540

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
0
Attacker Value
Unknown

CVE-2024-55539

Disclosure Date: December 23, 2024 (last updated January 05, 2025)
Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185.
0
Attacker Value
Unknown

CVE-2024-11297

Disclosure Date: December 20, 2024 (last updated December 21, 2024)
The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
0
Attacker Value
Unknown

CVE-2024-12569

Disclosure Date: December 19, 2024 (last updated January 13, 2025)
Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in the Recording Server under specific conditions.
0
Attacker Value
Unknown

CVE-2024-11280

Disclosure Date: December 17, 2024 (last updated December 18, 2024)
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
Attacker Value
Unknown

CVE-2023-33996

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10.
0