Show filters
2,041 Total Results
Displaying 81-90 of 2,041
Sort by:
Attacker Value
Unknown

CVE-2024-26154

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting in the appliance site name. The ETIC RAS web server saves the site name and then presents it to the administrators in a few different pages.
0
Attacker Value
Unknown

CVE-2024-26153

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device.
0
Attacker Value
Unknown

CVE-2025-22773

Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in WPChill Htaccess File Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Htaccess File Editor: from n/a through 1.0.19.
0
Attacker Value
Unknown

CVE-2025-21395

Disclosure Date: January 14, 2025 (last updated January 18, 2025)
Microsoft Access Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21366

Disclosure Date: January 14, 2025 (last updated January 18, 2025)
Microsoft Access Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-0107

Disclosure Date: January 11, 2025 (last updated January 16, 2025)
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
0
Attacker Value
Unknown

CVE-2025-0106

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.
0
Attacker Value
Unknown

CVE-2025-0105

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem.
0
Attacker Value
Unknown

CVE-2025-0104

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition browser-session theft.
0
Attacker Value
Unknown

CVE-2025-0103

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
0