CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2024-55215

Description: An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.

EPSS Score: 0.04%

Source: CVE
February 8th, 2025 (5 months ago)

CVE-2024-55214

Description: Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality.

EPSS Score: 0.04%

Source: CVE
February 8th, 2025 (5 months ago)

CVE-2024-55213

Description: Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function.

EPSS Score: 0.04%

Source: CVE
February 8th, 2025 (5 months ago)

CVE-2024-52884

Description: An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.

EPSS Score: 0.04%

Source: CVE
February 8th, 2025 (5 months ago)

CVE-2024-52883

Description: An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.

EPSS Score: 0.04%

Source: CVE
February 8th, 2025 (5 months ago)

CVE-2024-52882

Description: An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.

EPSS Score: 0.04%

Source: CVE
February 8th, 2025 (5 months ago)

CVE-2024-52881

Description: An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.

EPSS Score: 0.04%

Source: CVE
February 8th, 2025 (5 months ago)

CVE-2024-48091

Description: Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL.

EPSS Score: 0.04%

Source: CVE
February 8th, 2025 (5 months ago)

CVE-2024-37455

Description: Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.31.

CVSS: HIGH (8.8)

EPSS Score: 0.05%

Source: CVE
February 8th, 2025 (5 months ago)

CVE-2024-35106

Description: NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to cause a Denial of Service (DoS) or potentially arbitrary code execution via a crafted POST request.

EPSS Score: 0.05%

Source: CVE
February 8th, 2025 (5 months ago)