Show filters
1,423 Total Results
Displaying 41-50 of 1,423
Sort by:
Attacker Value
Unknown
CVE-2024-56413
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
0
Attacker Value
Unknown
CVE-2024-55543
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
0
Attacker Value
Unknown
CVE-2024-55542
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895.
0
Attacker Value
Unknown
CVE-2024-55541
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
0
Attacker Value
Unknown
CVE-2024-55540
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
0
Attacker Value
Unknown
CVE-2024-55539
Disclosure Date: December 23, 2024 (last updated January 05, 2025)
Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185.
0
Attacker Value
Unknown
CVE-2024-11297
Disclosure Date: December 20, 2024 (last updated December 21, 2024)
The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
0
Attacker Value
Unknown
CVE-2024-12569
Disclosure Date: December 19, 2024 (last updated January 13, 2025)
Disclosure
of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera
credentials stored in the Recording Server under specific conditions.
0
Attacker Value
Unknown
CVE-2024-11280
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
0
Attacker Value
Unknown
CVE-2023-33996
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10.
0