Show filters
2,041 Total Results
Displaying 81-90 of 2,041
Sort by:
Attacker Value
Unknown
CVE-2024-26154
Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting in the appliance site
name. The ETIC RAS web server saves the site name and then presents it
to the administrators in a few different pages.
0
Attacker Value
Unknown
CVE-2024-26153
Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19
are vulnerable to cross-site request forgery (CSRF). An external
attacker with no access to the device can force the end user into
submitting a "setconf" method request, not requiring any CSRF token,
which can lead into denial of service on the device.
0
Attacker Value
Unknown
CVE-2025-22773
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in WPChill Htaccess File Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Htaccess File Editor: from n/a through 1.0.19.
0
Attacker Value
Unknown
CVE-2025-21395
Disclosure Date: January 14, 2025 (last updated January 18, 2025)
Microsoft Access Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2025-21366
Disclosure Date: January 14, 2025 (last updated January 18, 2025)
Microsoft Access Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2025-0107
Disclosure Date: January 11, 2025 (last updated January 16, 2025)
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
0
Attacker Value
Unknown
CVE-2025-0106
Disclosure Date: January 11, 2025 (last updated January 12, 2025)
A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.
0
Attacker Value
Unknown
CVE-2025-0105
Disclosure Date: January 11, 2025 (last updated January 12, 2025)
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem.
0
Attacker Value
Unknown
CVE-2025-0104
Disclosure Date: January 11, 2025 (last updated January 12, 2025)
A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition browser-session theft.
0
Attacker Value
Unknown
CVE-2025-0103
Disclosure Date: January 11, 2025 (last updated January 12, 2025)
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
0