Show filters
2,041 Total Results
Displaying 71-80 of 2,041
Sort by:
Attacker Value
Unknown
CVE-2025-24503
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
0
Attacker Value
Unknown
CVE-2025-24502
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
0
Attacker Value
Unknown
CVE-2025-24501
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.
0
Attacker Value
Unknown
CVE-2025-24500
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
The vulnerability allows an unauthenticated attacker to access information in PAM database.
0
Attacker Value
Unknown
CVE-2025-24610
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christian Leuenberg, L.net Web Solutions Restrict Anonymous Access allows Stored XSS. This issue affects Restrict Anonymous Access: from n/a through 1.2.
0
Attacker Value
Unknown
CVE-2025-23725
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TaskMeister Accessibility Task Manager allows Reflected XSS. This issue affects Accessibility Task Manager: from n/a through 1.2.1.
0
Attacker Value
Unknown
CVE-2024-45647
Disclosure Date: January 20, 2025 (last updated January 30, 2025)
IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.
0
Attacker Value
Unknown
CVE-2024-26157
Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting (XSS) attacks in get
view method under view parameter. The ETIC RAS web server uses dynamic
pages that get their input from the client side and reflect the input in
their response to the client.
0
Attacker Value
Unknown
CVE-2024-26156
Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting (XSS) attacks in the
method parameter. The ETIC RAS web server uses dynamic pages that gets
their input from the client side and reflects the input in its response
to the client.
0
Attacker Value
Unknown
CVE-2024-26155
Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
expose clear text credentials in the web portal. An attacker can access
the ETIC RAS web portal and view the HTML code, which is configured to
be hidden, thus allowing a connection to the ETIC RAS ssh server, which
could enable an attacker to perform actions on the device.
0