4.6

CVSS4.0

CVE-2025-0619 - Unsafe stored password recovery

Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords

πŸ“… Published: Jan. 23, 2025, 11:07 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 11:16 a.m.

5.9

CVSS4.0

CVE-2025-0648 - M-Files Server crash via EOT database driver configuration

Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of service via configuration change.

πŸ“… Published: Jan. 23, 2025, 11:06 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 11:16 a.m.

6.5

CVSS3.1

CVE-2024-43708 -

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of inputs in Kibana UI. This can be carried out by users with read access to any feature in Kibana.

πŸ“… Published: Jan. 23, 2025, 10:27 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:56 p.m.

8.4

CVSS4.0

CVE-2024-12957 -

A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

πŸ“… Published: Jan. 23, 2025, 9:41 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-13593 - BMLT Meeting Map <= 2.6.0 - Authenticated (Contributor+) Local File Inclusion

The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.0 via the 'bmlt_meeting_map' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on th…

πŸ“… Published: Jan. 23, 2025, 9:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:20 p.m.

4.3

CVSS3.1

CVE-2024-13511 - Variation Swatches for WooCommerce 1.0.8 - 1.3.2 - Cross-Site Request Forgery to Plugin Settings Re…

The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query …

πŸ“… Published: Jan. 23, 2025, 9:21 a.m. πŸ”„ Last Modified: Feb. 5, 2025, 6:22 p.m.

6.5

CVSS3.1

CVE-2024-53299 - Apache Wicket: An attacker can intentionally trigger a memory leak

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.

πŸ“… Published: Jan. 23, 2025, 8:37 a.m. πŸ”„ Last Modified: June 27, 2025, 7:41 p.m.

9

CVSS3.1

CVE-2024-52975 - Fleet Server sensitive information exposure via logs

An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.

πŸ“… Published: Jan. 23, 2025, 7:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-52972 - Kibana allocation of resources without limits or throttling leads to crash

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot. This can be carried out by users with read access to the Observability Metrics or Logs features in Kibana.

πŸ“… Published: Jan. 23, 2025, 6:11 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:57 p.m.

7.7

CVSS3.1

CVE-2024-43707 - Kibana exposure of sensitive information to an unauthorized actor

An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature of the sensitive information depends on the integrations enabled for the Elastic Agent and their respective versions.

πŸ“… Published: Jan. 23, 2025, 6:08 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:59 p.m.
Total resulsts: 349182
Page 6990 of 34,919
Β« previous page Β» next page
Filters