Show filters
3,312 Total Results
Displaying 91-100 of 3,312
Sort by:
Attacker Value
Unknown
CVE-2024-4762
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.
0
Attacker Value
Unknown
CVE-2024-54411
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in hosting.io, campaigns.io WP Controller allows Stored XSS.This issue affects WP Controller: from n/a through 3.2.0.
0
Attacker Value
Unknown
CVE-2024-54233
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enea Overclokk Advanced Control Manager for WordPress by ItalyStrap allows Reflected XSS.This issue affects Advanced Control Manager for WordPress by ItalyStrap: from n/a through 2.16.0.
0
Attacker Value
Unknown
CVE-2024-41146
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS communication cabling to perform a Denial-of-Service attack against HBUS connected devices, require a device reboot to resolve.
This issue affects: Controller 6000 and Controller 7000 firmware versions 9.10 prior to vCR9.10.241108a (distributed in 9.10.2149 (MR4)), 9.00 prior to vCR9.00.241108a (distributed in 9.00.2374 (MR5)), 8.90 prior to vCR8.90.241107a (distributed in 8.90.2356 (MR6)), all versions of 8.80 and prior.
0
Attacker Value
Unknown
CVE-2024-8496
Disclosure Date: December 11, 2024 (last updated December 18, 2024)
Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.
0
Attacker Value
Unknown
CVE-2024-11598
Disclosure Date: December 11, 2024 (last updated January 24, 2025)
Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.
0
Attacker Value
Unknown
CVE-2024-10251
Disclosure Date: December 11, 2024 (last updated December 18, 2024)
Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.
0
Attacker Value
Unknown
CVE-2024-11737
Disclosure Date: December 11, 2024 (last updated December 21, 2024)
CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of
confidentiality, integrity of the controller when an unauthenticated crafted Modbus packet is sent to the device.
0
Attacker Value
Unknown
CVE-2024-10256
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
0
Attacker Value
Unknown
CVE-2023-29239
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LuckyWP Scripts Control: from n/a through 1.2.1.
0