Show filters
721 Total Results
Displaying 41-50 of 721
Sort by:
Attacker Value
Unknown
CVE-2021-42305
Disclosure Date: November 10, 2021 (last updated November 28, 2024)
Microsoft Exchange Server Spoofing Vulnerability
1
Attacker Value
Unknown
CVE-2023-38185
Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Microsoft Exchange Server Remote Code Execution Vulnerability
1
Attacker Value
Unknown
CVE-2024-26198
Disclosure Date: March 12, 2024 (last updated February 26, 2025)
Microsoft Exchange Server Remote Code Execution Vulnerability
1
Attacker Value
Very High
CVE-2020-25223
Last updated September 23, 2020
A remote code execution vulnerability in the WebAdmin of SG UTM was recently discovered and responsibly disclosed to Sophos. It was reported via the Sophos bug bounty program by an external security researcher. The vulnerability has been fixed.
Sophos would like to thank Łukasz Rupala for responsibly disclosing this issue to Sophos.
The remediation prevented users from remotely executing arbitrary code. There was no evidence that the vulnerability was exploited and to our knowledge no customers are impacted.
Fix included in SG UTM v9.705 MR5, v9.607 MR7, and v9.511 MR11 on September 17, 2020
Users of older versions of SG UTM are required to upgrade to receive this fix
Workaround
Customers can protect themselves by ensuring their WebAdmin is not exposed to WAN.
This can be achieved by keeping Internal (LAN) (Network) or another internal-only network definition as the sole entry in Management→WebAdmin Settings→WebAdmin Access Configuration→Allowed Networks.
3
Attacker Value
High
CVE-2022-22956
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
3
Attacker Value
Low
CVE-2021-32648
Disclosure Date: August 26, 2021 (last updated February 23, 2025)
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.
3
Attacker Value
Unknown
CVE-2021-21980
Disclosure Date: November 24, 2021 (last updated October 07, 2023)
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
1
Attacker Value
Very High
CVE-2023-46805
Disclosure Date: January 12, 2024 (last updated February 26, 2025)
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
7
Attacker Value
Moderate
CVE-2023-0315
Disclosure Date: January 16, 2023 (last updated February 24, 2025)
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
3
Attacker Value
Very High
CVE-2021-42668
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a remote code execution on the remote web server.
3