Show filters
290 Total Results
Displaying 1-10 of 290
Sort by:
Attacker Value
Very High

CVE-2021-3156 "Baron Samedit"

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Attacker Value
Unknown

CVE-2025-1039

Disclosure Date: February 20, 2025 (last updated February 27, 2025)
The Lenix Elementor Leads addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a URL form field in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2025-23114

Disclosure Date: February 05, 2025 (last updated February 05, 2025)
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.
0
Attacker Value
Unknown

CVE-2024-56242

Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tyche Softwares Arconix Shortcodes allows Stored XSS.This issue affects Arconix Shortcodes: from n/a through 2.1.14.
0
Attacker Value
Unknown

CVE-2024-10476

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may allow an attacker to shut down or otherwise impact the availability of the system. Note: BD Synapsys™ Informatics Solution is only in scope of this vulnerability when installed on a NUC server. BD Synapsys™ Informatics Solution installed on a customer-provided virtual machine or on the BD Kiestra™ SCU hardware is not in scope.
0
Attacker Value
Unknown

CVE-2024-45663

Disclosure Date: November 21, 2024 (last updated December 21, 2024)
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
0
Attacker Value
Unknown

CVE-2024-52432

Disclosure Date: November 18, 2024 (last updated February 27, 2025)
Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through 0.0.4.
Attacker Value
Unknown

CVE-2024-11206

Disclosure Date: November 14, 2024 (last updated February 27, 2025)
Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.
0
Attacker Value
Unknown

CVE-2024-38783

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Tyche Softwares Arconix FAQ allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Arconix FAQ: from n/a through 1.9.4.
0
Attacker Value
Unknown

CVE-2024-38769

Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Tyche Softwares Arconix Shortcodes allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Arconix Shortcodes: from n/a through 2.1.11.
0