Total
401 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-2001 | 1 Gitlab | 1 Gitlab | 2025-01-07 | 4.3 Medium |
An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could potentially lead a victim to download malicious code. | ||||
CVE-2024-12108 | 2 Microsoft, Progress | 2 Windows, Whatsup Gold | 2025-01-06 | 9.6 Critical |
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API. | ||||
CVE-2023-2807 | 1 Pandorafms | 1 Pandora Fms | 2025-01-03 | 6.4 Medium |
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms. | ||||
CVE-2022-36331 | 1 Westerndigital | 24 My Cloud, My Cloud Dl2100, My Cloud Dl2100 Firmware and 21 more | 2025-01-03 | 10 Critical |
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102. | ||||
CVE-2022-35770 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2025-01-02 | 6.5 Medium |
Windows NTLM Spoofing Vulnerability | ||||
CVE-2022-34689 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2025-01-02 | 7.5 High |
Windows CryptoAPI Spoofing Vulnerability | ||||
CVE-2022-44713 | 1 Microsoft | 2 Office, Office Long Term Servicing Channel | 2025-01-02 | 7.5 High |
Microsoft Outlook for Mac Spoofing Vulnerability | ||||
CVE-2022-26910 | 1 Microsoft | 1 Skype For Business Server | 2025-01-02 | 5.3 Medium |
Skype for Business and Lync Spoofing Vulnerability | ||||
CVE-2024-13061 | 2025-01-02 | 9.8 Critical | ||
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system. | ||||
CVE-2024-30058 | 2024-12-31 | 5.4 Medium | ||
Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||||
CVE-2024-20674 | 1 Microsoft | 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more | 2024-12-31 | 8.8 High |
Windows Kerberos Security Feature Bypass Vulnerability | ||||
CVE-2024-54450 | 2024-12-28 | 9.4 Critical | ||
An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that the user logged in from. This fake IP address can later be displayed in the My Account popup that shows the IP address that was used to log in. | ||||
CVE-2024-55232 | 2024-12-26 | 5.4 Medium | ||
An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information. | ||||
CVE-2024-55470 | 2024-12-20 | 7.5 High | ||
Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the application relies on client-side information for authentication. | ||||
CVE-2023-34157 | 1 Huawei | 1 Harmonyos | 2024-12-17 | 10 Critical |
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app. | ||||
CVE-2022-48469 | 1 Huawei | 2 B535-232a, B535-232a Firmware | 2024-12-17 | 6.5 Medium |
There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers. | ||||
CVE-2024-28228 | 1 Jetbrains | 1 Youtrack | 2024-12-16 | 5.3 Medium |
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible | ||||
CVE-2023-41133 | 2024-12-13 | 5.3 Medium | ||
Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0. | ||||
CVE-2023-34167 | 1 Huawei | 1 Emui | 2024-12-12 | 5.3 Medium |
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled. | ||||
CVE-2023-34160 | 1 Huawei | 1 Emui | 2024-12-12 | 5.3 Medium |
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled. |