Show filters
2,041 Total Results
Displaying 71-80 of 2,041
Sort by:
Attacker Value
Unknown

CVE-2025-24503

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
0
Attacker Value
Unknown

CVE-2025-24502

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
0
Attacker Value
Unknown

CVE-2025-24501

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.
0
Attacker Value
Unknown

CVE-2025-24500

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
The vulnerability allows an unauthenticated attacker to access information in PAM database.
0
Attacker Value
Unknown

CVE-2025-24610

Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christian Leuenberg, L.net Web Solutions Restrict Anonymous Access allows Stored XSS. This issue affects Restrict Anonymous Access: from n/a through 1.2.
0
Attacker Value
Unknown

CVE-2025-23725

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TaskMeister Accessibility Task Manager allows Reflected XSS. This issue affects Accessibility Task Manager: from n/a through 1.2.1.
0
Attacker Value
Unknown

CVE-2024-45647

Disclosure Date: January 20, 2025 (last updated January 30, 2025)
IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.
Attacker Value
Unknown

CVE-2024-26157

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in get view method under view parameter. The ETIC RAS web server uses dynamic pages that get their input from the client side and reflect the input in their response to the client.
0
Attacker Value
Unknown

CVE-2024-26156

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. The ETIC RAS web server uses dynamic pages that gets their input from the client side and reflects the input in its response to the client.
0
Attacker Value
Unknown

CVE-2024-26155

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the ETIC RAS web portal and view the HTML code, which is configured to be hidden, thus allowing a connection to the ETIC RAS ssh server, which could enable an attacker to perform actions on the device.
0