Show filters
3,556 Total Results
Displaying 81-90 of 3,556
Sort by:
Attacker Value
Unknown
CVE-2025-23086
Disclosure Date: January 21, 2025 (last updated January 21, 2025)
On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.
0
Attacker Value
Unknown
CVE-2025-0430
Disclosure Date: January 17, 2025 (last updated January 18, 2025)
Belledonne Communications Linphone-Desktop
is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2025-23040
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL. GitHub Desktop relies on Git to perform all network related operations (such as cloning, fetching, and pushing). When a user attempts to clone a repository GitHub Desktop will invoke `git clone` and when Git encounters a remote which requires authentication it will request the credentials for that remote host from GitHub Desktop using the git-credential protocol. Using a maliciously crafted URL it's possible to cause the credential request coming from Git to be misinterpreted by Github Desktop such that it will send credentials for a different host than the host that Git is currently communicating with thereby allowing for secret exfiltration. GitHub username and OAuth token, or credentials for other Git remot…
0
Attacker Value
Unknown
CVE-2025-21187
Disclosure Date: January 14, 2025 (last updated February 06, 2025)
Microsoft Power Automate Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-4996
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affects Wapro ERP Desktop versions before 8.90.0.
0
Attacker Value
Unknown
CVE-2024-4995
Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0.
0
Attacker Value
Unknown
CVE-2024-49105
Disclosure Date: December 12, 2024 (last updated January 13, 2025)
Remote Desktop Client Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-7572
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
0
Attacker Value
Unknown
CVE-2024-12149
Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.
0
Attacker Value
Unknown
CVE-2024-11672
Disclosure Date: November 25, 2024 (last updated January 05, 2025)
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.
0