Show filters
1,086 Total Results
Displaying 71-80 of 1,086
Sort by:
Attacker Value
Unknown

CVE-2025-0053

Disclosure Date: January 14, 2025 (last updated February 27, 2025)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and may be leveraged to facilitate further attacks or exploits.
0
Attacker Value
Unknown

CVE-2024-12401

Disclosure Date: December 12, 2024 (last updated February 27, 2025)
A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager reads, for example, in a Secret resource, to use large amounts of CPU in the cert-manager controller pod to effectively create a denial-of-service (DoS) vector for the cert-manager in the cluster.
Attacker Value
Unknown

CVE-2024-49065

Disclosure Date: December 12, 2024 (last updated February 27, 2025)
Microsoft Office Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-50585

Disclosure Date: December 11, 2024 (last updated February 27, 2025)
Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request.  The vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor and request a patch.
0
Attacker Value
Unknown

CVE-2024-47585

Disclosure Date: December 10, 2024 (last updated February 27, 2025)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied for both, which may contribute to these risks. On successful exploitation, this can result in potential security concerns. However, it has no impact on the integrity and availability of the application and may have only a low impact on data confidentiality.
0
Attacker Value
Unknown

CVE-2024-10127

Disclosure Date: November 20, 2024 (last updated February 27, 2025)
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
0
Attacker Value
Unknown

CVE-2024-10126

Disclosure Date: November 20, 2024 (last updated February 27, 2025)
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
0
Attacker Value
Unknown

CVE-2024-32048

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
0
Attacker Value
Unknown

CVE-2024-49026

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-47586

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable. There is no impact on Confidentiality or Integrity.
0