Show filters
977 Total Results
Displaying 81-90 of 977
Sort by:
Attacker Value
Unknown

CVE-2023-52947

Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be affected by the logout.
Attacker Value
Unknown

CVE-2024-8767

Disclosure Date: September 17, 2024 (last updated September 17, 2024)
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.
0
Attacker Value
Unknown

CVE-2024-7689

Disclosure Date: September 09, 2024 (last updated October 08, 2024)
The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Attacker Value
Unknown

CVE-2024-40714

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
0
Attacker Value
Unknown

CVE-2024-40713

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
0
Attacker Value
Unknown

CVE-2024-40712

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
0
Attacker Value
Unknown

CVE-2024-40710

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.
0
Attacker Value
Unknown

CVE-2024-40709

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.
0
Attacker Value
Unknown

CVE-2024-39718

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
0
Attacker Value
Unknown

CVE-2024-43269

Disclosure Date: August 26, 2024 (last updated September 13, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.