Show filters
2,134 Total Results
Displaying 51-60 of 2,134
Sort by:
Attacker Value
Unknown
CVE-2024-38657
Disclosure Date: February 21, 2025 (last updated February 23, 2025)
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
0
Attacker Value
Unknown
CVE-2024-13538
Disclosure Date: February 18, 2025 (last updated February 18, 2025)
The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.19. This is due the /vendor/cocur/slugify/bin/generate-default.php file being directly accessible and triggering an error. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
0
Attacker Value
Unknown
CVE-2024-39797
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
Improper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access.
0
Attacker Value
Unknown
CVE-2024-39779
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
Stack-based buffer overflow in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access.
0
Attacker Value
Unknown
CVE-2024-23563
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
0
Attacker Value
Unknown
CVE-2025-22467
Disclosure Date: February 11, 2025 (last updated February 21, 2025)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-13843
Disclosure Date: February 11, 2025 (last updated February 21, 2025)
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
0
Attacker Value
Unknown
CVE-2024-13842
Disclosure Date: February 11, 2025 (last updated February 21, 2025)
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
0
Attacker Value
Unknown
CVE-2024-13830
Disclosure Date: February 11, 2025 (last updated February 14, 2025)
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
0
Attacker Value
Unknown
CVE-2024-12058
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
0