Show filters
1,997 Total Results
Displaying 61-70 of 1,997
Sort by:
Attacker Value
Unknown
CVE-2025-24376
Disclosure Date: January 30, 2025 (last updated February 27, 2025)
kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy and AdmissionPolicyGroup can evaluate only namespaced resources. The resources to be evaluated are determined by the rules provided by the user when defining the policy. There might be Kubernetes namespaced resources that should not be validated by AdmissionPolicy and by the AdmissionPolicyGroup policies because of their sensitive nature. For example, PolicyReport are namespaced resources that contain the list of non compliant objects found inside of a namespace. An attacker can use either an AdmissionPolicy or an AdmissionPolicyGroup to prevent the creation and update of PolicyReport objects to hide non-compliant resources. Moreover, the same attacker might use a mutating AdmissionPolicy to alter the contents of the PolicyReport created inside of the namespace. Starting from the 1.21.0 release, the validation rules applied to AdmissionPoli…
0
Attacker Value
Unknown
CVE-2025-23830
Disclosure Date: January 16, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jobair JB Horizontal Scroller News Ticker allows DOM-Based XSS.This issue affects JB Horizontal Scroller News Ticker: from n/a through 1.0.
0
Attacker Value
Unknown
CVE-2025-23467
Disclosure Date: January 16, 2025 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Vimal Ghorecha RSS News Scroller allows Stored XSS.This issue affects RSS News Scroller: from n/a through 2.0.0.
0
Attacker Value
Unknown
CVE-2018-25108
Disclosure Date: January 16, 2025 (last updated February 27, 2025)
An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.
0
Attacker Value
Unknown
CVE-2024-12083
Disclosure Date: January 14, 2025 (last updated February 27, 2025)
Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.
0
Attacker Value
Unknown
CVE-2024-50603
Disclosure Date: January 08, 2025 (last updated February 27, 2025)
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
0
Attacker Value
Unknown
CVE-2024-40702
Disclosure Date: January 07, 2025 (last updated February 27, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.
0
Attacker Value
Unknown
CVE-2024-28778
Disclosure Date: January 07, 2025 (last updated February 27, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.
0
Attacker Value
Unknown
CVE-2024-25037
Disclosure Date: January 07, 2025 (last updated February 27, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
0
Attacker Value
Unknown
CVE-2022-22363
Disclosure Date: January 07, 2025 (last updated February 27, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
0