Show filters
1,423 Total Results
Displaying 71-80 of 1,423
Sort by:
Attacker Value
Unknown

CVE-2024-49382

Disclosure Date: October 15, 2024 (last updated February 05, 2025)
Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Attacker Value
Unknown

CVE-2024-9473

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect.
Attacker Value
Unknown

CVE-2024-3506

Disclosure Date: October 08, 2024 (last updated October 08, 2024)
A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict conditions.
0
Attacker Value
Unknown

CVE-2022-4534

Disclosure Date: October 08, 2024 (last updated January 06, 2025)
The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.
0
Attacker Value
Unknown

CVE-2024-47306

Disclosure Date: October 06, 2024 (last updated October 07, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking allows Stored XSS.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.2.3.
0
Attacker Value
Unknown

CVE-2024-8903

Disclosure Date: September 23, 2024 (last updated September 23, 2024)
Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.
0
Attacker Value
Unknown

CVE-2024-8766

Disclosure Date: September 16, 2024 (last updated January 07, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235, Acronis Cyber Protect 16 (Windows) before build 39169.
0
Attacker Value
Unknown

CVE-2024-34016

Disclosure Date: September 16, 2024 (last updated September 17, 2024)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.
0
Attacker Value
Unknown

CVE-2024-8687

Disclosure Date: September 11, 2024 (last updated October 03, 2024)
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so.
Attacker Value
Unknown

CVE-2024-6889

Disclosure Date: September 04, 2024 (last updated October 08, 2024)
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).