Show filters
213 Total Results
Displaying 81-90 of 213
Sort by:
Attacker Value
Unknown
CVE-2024-2448
Disclosure Date: March 22, 2024 (last updated February 12, 2025)
An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.
0
Attacker Value
Unknown
CVE-2024-2291
Disclosure Date: March 20, 2024 (last updated January 17, 2025)
In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.
0
Attacker Value
Unknown
CVE-2024-1856
Disclosure Date: March 20, 2024 (last updated January 17, 2025)
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-1801
Disclosure Date: March 20, 2024 (last updated January 17, 2025)
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-1636
Disclosure Date: February 28, 2024 (last updated December 18, 2024)
Potential Cross-Site Scripting (XSS) in the page editing area.
0
Attacker Value
Unknown
CVE-2024-1632
Disclosure Date: February 28, 2024 (last updated December 18, 2024)
Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.
0
Attacker Value
Unknown
CVE-2024-1403
Disclosure Date: February 27, 2024 (last updated February 12, 2025)
In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified. The
vulnerability is a bypass to authentication based on a failure to properly
handle username and password. Certain unexpected
content passed into the credentials can lead to unauthorized access without proper
authentication.
0
Attacker Value
Unknown
CVE-2024-1212
Disclosure Date: February 21, 2024 (last updated November 20, 2024)
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
0
Attacker Value
Unknown
CVE-2024-1474
Disclosure Date: February 21, 2024 (last updated January 06, 2025)
In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.
0
Attacker Value
Unknown
CVE-2024-0833
Disclosure Date: January 31, 2024 (last updated February 10, 2024)
In Telerik Test Studio versions prior to
v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.
0