Show filters
3,267 Total Results
Displaying 51-60 of 3,267
Sort by:
Attacker Value
Unknown
CVE-2024-55904
Disclosure Date: February 14, 2025 (last updated February 14, 2025)
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
0
Attacker Value
Unknown
CVE-2024-13701
Disclosure Date: February 12, 2025 (last updated February 12, 2025)
The Liveticker (by stklcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'liveticker' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2025-24042
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2025-24039
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Visual Studio Code Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-53977
Disclosure Date: February 11, 2025 (last updated February 11, 2025)
A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows a specific executable file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch the script from a user-writable directory.
0
Attacker Value
Unknown
CVE-2024-45386
Disclosure Date: February 11, 2025 (last updated February 11, 2025)
A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions < V19 Update 1), TIA Administrator (All versions < V3.0.4). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.
0
Attacker Value
Unknown
CVE-2025-24876
Disclosure Date: February 11, 2025 (last updated February 11, 2025)
The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application
0
Attacker Value
Unknown
CVE-2025-24868
Disclosure Date: February 11, 2025 (last updated February 11, 2025)
The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation. On successful exploitation attacker can cause limited impact on confidentiality, integrity, and availability of the system.
0
Attacker Value
Unknown
CVE-2024-8550
Disclosure Date: February 10, 2025 (last updated February 11, 2025)
A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary files from the server, including sensitive files such as API keys, by manipulating the filename parameter. The issue arises due to improper sanitization of user input passed to the os.path.join function, which can be exploited to access files outside the intended directory.
0
Attacker Value
Unknown
CVE-2024-54176
Disclosure Date: February 08, 2025 (last updated February 09, 2025)
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14 and 7.3 through 7.3.2 could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
0