CVE-2025-2572
- EPSS 0.01%
- Veröffentlicht 14.04.2025 16:06:45
- Zuletzt bearbeitet 17.07.2025 14:41:45
In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.
CVE-2024-12108
- EPSS 1%
- Veröffentlicht 31.12.2024 11:15:06
- Zuletzt bearbeitet 06.01.2025 16:51:11
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
CVE-2024-12106
- EPSS 1.79%
- Veröffentlicht 31.12.2024 11:15:06
- Zuletzt bearbeitet 06.01.2025 16:54:14
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
CVE-2024-12105
- EPSS 0.24%
- Veröffentlicht 31.12.2024 11:15:06
- Zuletzt bearbeitet 08.01.2025 14:15:25
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.
CVE-2024-8785
- EPSS 0.25%
- Veröffentlicht 02.12.2024 15:15:12
- Zuletzt bearbeitet 09.12.2024 20:25:23
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.
CVE-2024-46909
- EPSS 3.38%
- Veröffentlicht 02.12.2024 15:15:12
- Zuletzt bearbeitet 10.12.2024 18:10:35
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
CVE-2024-46908
- EPSS 4.01%
- Veröffentlicht 02.12.2024 15:15:11
- Zuletzt bearbeitet 10.12.2024 18:23:09
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
CVE-2024-46907
- EPSS 3.37%
- Veröffentlicht 02.12.2024 15:15:11
- Zuletzt bearbeitet 10.12.2024 18:23:41
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
CVE-2024-46906
- EPSS 6.86%
- Veröffentlicht 02.12.2024 15:15:11
- Zuletzt bearbeitet 06.12.2024 21:51:59
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
CVE-2024-46905
- EPSS 4.01%
- Veröffentlicht 02.12.2024 15:15:11
- Zuletzt bearbeitet 03.12.2024 20:00:17
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.