Show filters
1,855 Total Results
Displaying 91-100 of 1,855
Sort by:
Attacker Value
Unknown
CVE-2024-42028
Disclosure Date: October 28, 2024 (last updated February 26, 2025)
A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (Version 8.4.62 and earlier) allows a malicious actor with a local operational system user to execute high privilege actions on UniFi Network Server.
0
Attacker Value
Unknown
CVE-2020-36831
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user.
0
Attacker Value
Unknown
CVE-2024-9873
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URLs in posts, comments, and profiles when Markdown support is enabled in all versions up to, and including, 6.4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-9158
Disclosure Date: September 30, 2024 (last updated February 26, 2025)
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
0
Attacker Value
Unknown
CVE-2024-20350
Disclosure Date: September 25, 2024 (last updated February 26, 2025)
A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance.
This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.
0
Attacker Value
Unknown
CVE-2024-42025
Disclosure Date: September 13, 2024 (last updated February 26, 2025)
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate privileges to root on the host device.
0
Attacker Value
Unknown
CVE-2024-8705
Disclosure Date: September 11, 2024 (last updated February 26, 2025)
A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDataKindByType of the file /DataSrvs/UCCGSrv.asmx. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-20381
Disclosure Date: September 11, 2024 (last updated February 26, 2025)
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device.
This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications to the configuration of the affected application or device, including creating new user accounts or elevating their own privileges on an affected system.
0
Attacker Value
Unknown
CVE-2024-43470
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-38188
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
0