Show filters
1,710 Total Results
Displaying 91-100 of 1,710
Sort by:
Attacker Value
Unknown

CVE-2024-23958

Disclosure Date: September 28, 2024 (last updated February 26, 2025)
Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the BLE AppAuthenRequest command handler. The handler uses hardcoded credentials as a fallback in case of an authentication request failure. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23196
Attacker Value
Unknown

CVE-2024-23957

Disclosure Date: September 28, 2024 (last updated February 26, 2025)
Autel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLB_HostHeartBeat handler of the DLB protocol implementation. When parsing an AES key, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23241
Attacker Value
Unknown

CVE-2024-7400

Disclosure Date: September 27, 2024 (last updated February 26, 2025)
The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.
0
Attacker Value
Unknown

CVE-2023-52950

Disclosure Date: September 26, 2024 (last updated February 26, 2025)
Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors.
Attacker Value
Unknown

CVE-2023-52949

Disclosure Date: September 26, 2024 (last updated February 26, 2025)
Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
Attacker Value
Unknown

CVE-2023-52948

Disclosure Date: September 26, 2024 (last updated February 26, 2025)
Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
Attacker Value
Unknown

CVE-2023-52947

Disclosure Date: September 26, 2024 (last updated February 26, 2025)
Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be affected by the logout.
Attacker Value
Unknown

CVE-2024-43188

Disclosure Date: September 18, 2024 (last updated February 26, 2025)
IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation.
Attacker Value
Unknown

CVE-2024-43460

Disclosure Date: September 17, 2024 (last updated February 26, 2025)
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
Attacker Value
Unknown

CVE-2024-7888

Disclosure Date: September 13, 2024 (last updated February 26, 2025)
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to, and including, 3.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify forms and various other settings.