Show filters
3,770 Total Results
Displaying 81-90 of 3,770
Sort by:
Attacker Value
Unknown

CVE-2017-3167

Disclosure Date: June 20, 2017 (last updated November 08, 2023)
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
Attacker Value
Unknown

CVE-2012-1889 - MS12-043 Microsoft XML Core Services MSXML Uninitialized Memory…

Disclosure Date: June 13, 2012 (last updated June 29, 2024)
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Attacker Value
Unknown

CVE-2025-1536

Disclosure Date: February 21, 2025 (last updated February 23, 2025)
A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects unknown code of the file /vpn/vpn_template_style.php of the component Request Parameter Handler. The manipulation of the argument stylenum leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2025-0916

Disclosure Date: February 19, 2025 (last updated February 20, 2025)
The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 2.4.9 to 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: The vulnerability has been initially patched in version 2.4.8 and was reintroduced in version 2.4.9 with the removal of the wp_kses_post() built-in WordPress sanitization function.
Attacker Value
Unknown

CVE-2025-24904

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to communicate with Signal servers. Prior to commit 82d70f6720e762898f34ae76b0894b0297d9b2f8, plaintext content envelopes could be injected by a server or a malicious client, and may have been able to bypass the end-to-end encryption and authentication. The vulnerability is fixed per 82d70f6720e762898f34ae76b0894b0297d9b2f8. The `Metadata` struct contains an additional `was_encrypted` field, which breaks the API, but should be easily resolvable. No known workarounds are available.
0
Attacker Value
Unknown

CVE-2025-24903

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to communicate with Signal servers. Prior to commit 82d70f6720e762898f34ae76b0894b0297d9b2f8, any contact may forge a sync message, impersonating another device of the local user. The origin of sync messages is not checked. Patched libsignal-service can be found after commit 82d70f6720e762898f34ae76b0894b0297d9b2f8. The `Metadata` struct contains an additional `was_encrypted` field, which breaks the API, but should be easily resolvable. No known workarounds are available.
0
Attacker Value
Unknown

CVE-2025-21376

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21375

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2025-21373

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Windows Installer Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2025-21371

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Windows Telephony Service Remote Code Execution Vulnerability