Show filters
2,048 Total Results
Displaying 41-50 of 2,048
Sort by:
Attacker Value
Unknown
CVE-2024-54293
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Incorrect Privilege Assignment vulnerability in CE21 CE21 Suite allows Privilege Escalation.This issue affects CE21 Suite: from n/a through 2.2.0.
0
Attacker Value
Unknown
CVE-2024-49597
Disclosure Date: November 26, 2024 (last updated February 05, 2025)
Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
0
Attacker Value
Unknown
CVE-2024-49596
Disclosure Date: November 26, 2024 (last updated February 05, 2025)
Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion
0
Attacker Value
Unknown
CVE-2024-49595
Disclosure Date: November 26, 2024 (last updated February 05, 2025)
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
0
Attacker Value
Unknown
CVE-2024-11075
Disclosure Date: November 19, 2024 (last updated November 20, 2024)
A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.
0
Attacker Value
Unknown
CVE-2024-51722
Disclosure Date: November 12, 2024 (last updated November 13, 2024)
A local privilege escalation vulnerability in the SecuSUITE Server (System Configuration) of SecuSUITE versions 5.0.420 and earlier could allow a successful attacker that had gained control of code running under one of the system accounts listed in the configuration file to potentially issue privileged script commands.
0
Attacker Value
Unknown
CVE-2024-51721
Disclosure Date: November 12, 2024 (last updated November 13, 2024)
A code injection vulnerability in the SecuSUITE Server Web Administration Portal of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially inject script commands or other executable content into the server that would run with root privilege.
0
Attacker Value
Unknown
CVE-2024-51720
Disclosure Date: November 12, 2024 (last updated November 13, 2024)
An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.
0
Attacker Value
Unknown
CVE-2024-10294
Disclosure Date: November 09, 2024 (last updated January 30, 2025)
The CE21 Suite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ce21_single_sign_on_save_api_settings' function in versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to change plugin settings.
0
Attacker Value
Unknown
CVE-2024-10285
Disclosure Date: November 09, 2024 (last updated January 30, 2025)
The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to log in the user associated with the JWT token.
0