Show filters
71,351 Total Results
Displaying 421-430 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-12356

Disclosure Date: December 17, 2024 (last updated December 21, 2024)
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Attacker Value
Very High

CVE-2024-55956

Disclosure Date: December 13, 2024 (last updated December 21, 2024)
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
Attacker Value
Very High

CVE-2024-11320

Disclosure Date: November 21, 2024 (last updated December 21, 2024)
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
Attacker Value
Unknown

CVE-2024-49033

Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Microsoft Word Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2024-43639

Disclosure Date: November 12, 2024 (last updated January 06, 2025)
Windows KDC Proxy Remote Code Execution Vulnerability
2
Attacker Value
Very Low

CVE-2024-43452

Disclosure Date: November 12, 2024 (last updated January 06, 2025)
Windows Registry Elevation of Privilege Vulnerability
1
Attacker Value
Moderate

CVE-2024-45519

Disclosure Date: October 02, 2024 (last updated October 16, 2024)
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
Attacker Value
Unknown

CVE-2024-38812

Disclosure Date: September 17, 2024 (last updated October 03, 2024)
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Attacker Value
Very High

CVE-2024-45195

Disclosure Date: September 04, 2024 (last updated September 06, 2024)
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
Attacker Value
Moderate

CVE-2024-28987

Disclosure Date: August 21, 2024 (last updated October 17, 2024)
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.