Show filters
455 Total Results
Displaying 1-10 of 455
Sort by:
Attacker Value
Very High
CVE-2017-5638
Disclosure Date: March 11, 2017 (last updated July 26, 2024)
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
1
Attacker Value
Very High
CVE-2020-7115
Disclosure Date: June 03, 2020 (last updated November 27, 2024)
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.
0
Attacker Value
Unknown
CVE-2024-42400
Disclosure Date: August 06, 2024 (last updated August 24, 2024)
Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.
0
Attacker Value
Unknown
CVE-2024-42399
Disclosure Date: August 06, 2024 (last updated August 24, 2024)
Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.
0
Attacker Value
Unknown
CVE-2024-42398
Disclosure Date: August 06, 2024 (last updated August 24, 2024)
Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.
0
Attacker Value
Unknown
CVE-2024-42395
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
0
Attacker Value
Unknown
CVE-2024-42394
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
0
Attacker Value
Unknown
CVE-2024-42393
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
0
Attacker Value
Unknown
CVE-2024-5486
Disclosure Date: July 30, 2024 (last updated September 12, 2024)
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager
0
Attacker Value
Unknown
CVE-2024-41916
Disclosure Date: July 30, 2024 (last updated September 12, 2024)
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.
0