Show filters
3,556 Total Results
Displaying 81-90 of 3,556
Sort by:
Attacker Value
Unknown

CVE-2025-23086

Disclosure Date: January 21, 2025 (last updated January 21, 2025)
On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.
0
Attacker Value
Unknown

CVE-2025-0430

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition.
0
Attacker Value
Unknown

CVE-2025-23040

Disclosure Date: January 15, 2025 (last updated January 16, 2025)
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL. GitHub Desktop relies on Git to perform all network related operations (such as cloning, fetching, and pushing). When a user attempts to clone a repository GitHub Desktop will invoke `git clone` and when Git encounters a remote which requires authentication it will request the credentials for that remote host from GitHub Desktop using the git-credential protocol. Using a maliciously crafted URL it's possible to cause the credential request coming from Git to be misinterpreted by Github Desktop such that it will send credentials for a different host than the host that Git is currently communicating with thereby allowing for secret exfiltration. GitHub username and OAuth token, or credentials for other Git remot…
0
Attacker Value
Unknown

CVE-2025-21187

Disclosure Date: January 14, 2025 (last updated February 06, 2025)
Microsoft Power Automate Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-4996

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affects Wapro ERP Desktop versions before 8.90.0.
0
Attacker Value
Unknown

CVE-2024-4995

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0.
0
Attacker Value
Unknown

CVE-2024-49105

Disclosure Date: December 12, 2024 (last updated January 13, 2025)
Remote Desktop Client Remote Code Execution Vulnerability
0
Attacker Value
Unknown

CVE-2024-7572

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
0
Attacker Value
Unknown

CVE-2024-12149

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.
0
Attacker Value
Unknown

CVE-2024-11672

Disclosure Date: November 25, 2024 (last updated January 05, 2025)
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.
0