Show filters
4,200 Total Results
Displaying 91-100 of 4,200
Sort by:
Attacker Value
Unknown
CVE-2024-45672
Disclosure Date: January 23, 2025 (last updated January 24, 2025)
IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service.
0
Attacker Value
Unknown
CVE-2025-23611
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WH Cache & Security allows Reflected XSS. This issue affects WH Cache & Security: from n/a through 1.1.2.
0
Attacker Value
Unknown
CVE-2024-45647
Disclosure Date: January 20, 2025 (last updated January 30, 2025)
IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.
0
Attacker Value
Unknown
CVE-2024-45654
Disclosure Date: January 19, 2025 (last updated January 19, 2025)
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.
0
Attacker Value
Unknown
CVE-2025-23820
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Laxman Thapa Content Security Policy Pro allows Cross Site Request Forgery.This issue affects Content Security Policy Pro: from n/a through 1.3.5.
0
Attacker Value
Unknown
CVE-2024-49375
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are: 1. The HTTP API must be enabled on the Rasa instance eg with `--enable-api`. This is not the default configuration. 2. For unauthenticated RCE to be exploitable, the user must not have configured any authentication or other security controls recommended in our documentation. 3. For authenticated RCE, the attacker must posses a valid authentication token or JWT to interact with the Rasa API. This issue has been addressed in rasa version 3.6.21 and all users are advised to upgrade. Users unable to upgrade should ensure that they require authentication and that only trusted users are given access.
0
Attacker Value
Unknown
CVE-2024-13275
Disclosure Date: January 09, 2025 (last updated January 10, 2025)
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.
0
Attacker Value
Unknown
CVE-2024-12715
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
0
Attacker Value
Unknown
CVE-2024-45640
Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-45100
Disclosure Date: January 07, 2025 (last updated January 08, 2025)
IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources.
0