Show filters
1,381 Total Results
Displaying 51-60 of 1,381
Sort by:
Attacker Value
Unknown

CVE-2024-51727

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a feature that could enable attackers to invalidate a legitimate user's session and cause a denial-of-service attack on a user's account.
Attacker Value
Unknown

CVE-2024-47547

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.
Attacker Value
Unknown

CVE-2024-47043

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone number and part of the email address.
Attacker Value
Unknown

CVE-2024-42494

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's services
Attacker Value
Unknown

CVE-2024-54213

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zionbuilder.io WordPress Page Builder – Zion Builder allows Stored XSS.This issue affects WordPress Page Builder – Zion Builder: from n/a through 3.6.12.
0
Attacker Value
Unknown

CVE-2024-45205

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point. Affected Products: UniFi iOS App (Version 10.17.7 and earlier) Mitigation: UniFi iOS App (Version 10.18.0 or later).
0
Attacker Value
Unknown

CVE-2024-53259

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICMP Packet Too Large packet. Since affected quic-go versions used IP_PMTUDISC_DO, the kernel would then return a "message too large" error on sendmsg, i.e. when quic-go attempts to send a packet that exceeds the MTU claimed in that ICMP packet. By setting this value to smaller than 1200 bytes (the minimum MTU for QUIC), the attacker can disrupt a QUIC connection. Crucially, this can be done after completion of the handshake, thereby circumventing any TCP fallback that might be implemented on the application layer (for example, many browsers fall back to HTTP over TCP if they're unable to establish a QUIC connection). The attacker needs to at least know the client's IP and port tuple to mount an attack. This vulnerability is fixed in 0.48.2.
0
Attacker Value
Unknown

CVE-2024-53751

Disclosure Date: December 02, 2024 (last updated February 06, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Abdul Hakeem Build App Online allows Cross Site Request Forgery.This issue affects Build App Online: from n/a through 1.0.22.
Attacker Value
Unknown

CVE-2024-53708

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in AutoQuiz AI Quiz allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AI Quiz: from n/a through 1.1.
0
Attacker Value
Unknown

CVE-2024-9044

Disclosure Date: November 29, 2024 (last updated December 21, 2024)
A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.
0