Show filters
3,312 Total Results
Displaying 81-90 of 3,312
Sort by:
Attacker Value
Unknown

CVE-2024-10630

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.
0
Attacker Value
Unknown

CVE-2024-12083

Disclosure Date: January 14, 2025 (last updated January 14, 2025)
Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.
0
Attacker Value
Unknown

CVE-2024-50603

Disclosure Date: January 08, 2025 (last updated January 24, 2025)
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
Attacker Value
Unknown

CVE-2024-40702

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.
Attacker Value
Unknown

CVE-2024-28778

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.
Attacker Value
Unknown

CVE-2024-25037

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
Attacker Value
Unknown

CVE-2022-22363

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2021-20455

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2023-47778

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LuckyWP Scripts Control: from n/a through 1.2.1.
0
Attacker Value
Unknown

CVE-2024-45387

Disclosure Date: December 23, 2024 (last updated February 12, 2025)
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.