Show filters
188 Total Results
Displaying 1-10 of 188
Sort by:
Attacker Value
Unknown

CVE-2024-4142

Disclosure Date: May 01, 2024 (last updated May 02, 2024)
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
1
Attacker Value
Unknown

CVE-2024-10083

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.
0
Attacker Value
Unknown

CVE-2025-0498

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.
0
Attacker Value
Unknown

CVE-2025-0497

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.
0
Attacker Value
Unknown

CVE-2025-0477

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.
0
Attacker Value
Unknown

CVE-2025-24482

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs to be executed with higher level permissions.
0
Attacker Value
Unknown

CVE-2025-24481

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote debugger port and can allow for unauthenticated access to the system configuration.
0
Attacker Value
Unknown

CVE-2025-24480

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack of input sanitation and could allow a remote attacker to run commands or code as a high privileged user.
0
Attacker Value
Unknown

CVE-2025-24479

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows access to the Command Prompt as a higher privileged user.
0
Attacker Value
Unknown

CVE-2024-22038

Disclosure Date: November 28, 2024 (last updated December 21, 2024)
Various problems in obs-scm-bridge allows attackers that create specially crafted git repositories to leak information of cause denial of service.
0