|
312701
|
- |
-
|
-
|
-
|
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory.
Malicious software runni…
|
-
|
CVE-2024-42416
|
2024-09-5 14:15 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312702
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montagereview via the displayinterval, speed, and scale pa…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43359
|
2024-09-5 06:43 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312703
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.6…
|
CWE-89
SQL Injection
|
CVE-2024-43360
|
2024-09-5 06:42 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312704
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the filter view via the filter[Id]. This vulnerability is fixe…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43358
|
2024-09-5 06:41 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312705
|
6.5 |
MEDIUM
Network
|
zoom
|
rooms_controller rooms meeting_software_development_kit workplace_virtual_desktop_infrastructure workplace_desktop workplace
|
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-42437
|
2024-09-5 06:39 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312706
|
6.5 |
MEDIUM
Network
|
zoom
|
rooms_controller rooms meeting_software_development_kit workplace_virtual_desktop_infrastructure workplace_desktop workplace
|
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-42436
|
2024-09-5 06:38 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312707
|
4.9 |
MEDIUM
Network
|
zoom
|
rooms_controller rooms meeting_software_development_kit workplace_virtual_desktop_infrastructure workplace_desktop workplace
|
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
|
NVD-CWE-noinfo
|
CVE-2024-42435
|
2024-09-5 06:36 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312708
|
4.9 |
MEDIUM
Network
|
zoom
|
rooms_controller rooms meeting_software_development_kit workplace_virtual_desktop_infrastructure workplace_desktop workplace
|
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
|
NVD-CWE-noinfo
|
CVE-2024-42434
|
2024-09-5 06:35 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312709
|
8.5 |
HIGH
Network
|
zoom
|
workplace workplace_desktop workplace_virtual_desktop_infrastructure rooms
|
Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-39825
|
2024-09-5 06:34 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312710
|
4.9 |
MEDIUM
Network
|
zoom
|
rooms_controller rooms meeting_software_development_kit workplace_virtual_desktop_infrastructure workplace_desktop workplace
|
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
|
NVD-CWE-noinfo
|
CVE-2024-39824
|
2024-09-5 06:32 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312711
|
4.9 |
MEDIUM
Network
|
zoom
|
rooms_controller rooms meeting_software_development_kit workplace_virtual_desktop_infrastructure workplace_desktop workplace
|
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
|
NVD-CWE-noinfo
|
CVE-2024-39823
|
2024-09-5 06:30 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312712
|
6.5 |
MEDIUM
Network
|
zoom
|
rooms_controller rooms meeting_software_development_kit workplace workplace_desktop
|
Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access.
|
NVD-CWE-noinfo
|
CVE-2024-39822
|
2024-09-5 06:28 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312713
|
7.8 |
HIGH
Local
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as this is a duplicate of CVE-2023-36540.
|
-
|
CVE-2023-34122
|
2024-09-5 04:15 |
2023-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312714
|
8.8 |
HIGH
Network
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as this is a duplicate of CVE-2023-36541.
|
-
|
CVE-2023-34113
|
2024-09-5 04:15 |
2023-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312715
|
8.3 |
HIGH
Network
|
zohocorp
|
manageengine_endpoint_central
|
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
|
CWE-863
Incorrect Authorization
|
CVE-2024-38868
|
2024-09-5 04:13 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312716
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the arg…
|
CWE-22
Path Traversal
|
CVE-2024-7927
|
2024-09-5 03:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312717
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to pa…
|
CWE-22
Path Traversal
|
CVE-2024-7926
|
2024-09-5 03:42 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312718
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: Let probe fail when workqueue cannot be enabled
The workqueue is enabled when the appropriate driver is loaded a…
|
CWE-476
NULL Pointer Dereference
|
CVE-2022-48868
|
2024-09-5 03:38 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312719
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: sdata can be NULL during AMPDU start
ieee80211_tx_ba_session_handle_start() may get NULL for sdata when a
deauthe…
|
CWE-476
NULL Pointer Dereference
|
CVE-2022-48875
|
2024-09-5 03:33 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312720
|
7.5 |
HIGH
Network
|
avtecinc
|
outpost_uploader_utility outpost_0810_firmware
|
Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.
|
CWE-219
Storage of File with Sensitive Data Under Web Root
|
CVE-2024-39776
|
2024-09-5 03:25 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312721
|
7.5 |
HIGH
Network
|
avtecinc
|
outpost_uploader_utility outpost_0810_firmware
|
Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2024-42418
|
2024-09-5 03:22 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312722
|
9.8 |
CRITICAL
Network
|
angeljudesuarez
|
e-commerce_website
|
A vulnerability has been found in itsourcecode E-Commerce Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file search_list.php. The manipulat…
|
CWE-89
SQL Injection
|
CVE-2024-8139
|
2024-09-5 03:02 |
2024-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312723
|
8.1 |
HIGH
Network
|
progress
|
ws_ftp_server
|
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in wit…
|
CWE-287
Improper Authentication
|
CVE-2024-7745
|
2024-09-5 02:57 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312724
|
6.5 |
MEDIUM
Network
|
progress
|
ws_ftp_server
|
In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Pr…
|
CWE-22
Path Traversal
|
CVE-2024-7744
|
2024-09-5 02:57 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312725
|
5.4 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.
|
NVD-CWE-noinfo
|
CVE-2024-39837
|
2024-09-5 02:38 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312726
|
8.8 |
HIGH
Network
|
easytest_online_test_platform_project
|
easytest_online_test_platform
|
SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.
|
CWE-89
SQL Injection
|
CVE-2024-7871
|
2024-09-5 02:34 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312727
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a…
|
NVD-CWE-noinfo
|
CVE-2024-39839
|
2024-09-5 02:34 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312728
|
5.4 |
MEDIUM
Network
|
phpoffice
|
phpspreadsheet
|
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In affected versions `\PhpOffice\PhpSpreadsheet\Writer\Html` doesn't sanitize spreadsheet styling information such as f…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45046
|
2024-09-5 02:32 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312729
|
6.5 |
MEDIUM
Network
|
phpoffice
|
phpspreadsheet
|
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker t…
|
CWE-611
XXE
|
CVE-2024-45048
|
2024-09-5 02:27 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312730
|
7.1 |
HIGH
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled, which allows a malicious remote to create…
|
NVD-CWE-noinfo
|
CVE-2024-41144
|
2024-09-5 02:25 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312731
|
7.8 |
HIGH
Local
|
qualcomm
|
fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware qcm4490_firmware qcm5430_firmware qcm6490_firmware qcm8550_firmware qcs4490_firmware qcs5430_firm…
|
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-33038
|
2024-09-5 02:21 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312732
|
7.5 |
HIGH
Network
|
qualcomm
|
ar8035_firmware csr8811_firmware fastconnect_6700_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_firmware immersive_home_214…
|
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33048
|
2024-09-5 02:20 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312733
|
7.8 |
HIGH
Local
|
qualcomm
|
ar8035_firmware csra6620_firmware csra6640_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_firmware…
|
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-33045
|
2024-09-5 02:20 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312734
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8017_firmware aqt1000_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware msm8108_firmwa…
|
Memory corruption when user provides data for FM HCI command control operations.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-33052
|
2024-09-5 02:18 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312735
|
7.5 |
HIGH
Network
|
qualcomm
|
315_5g_iot_firmware 9206_lte_firmware apq8017_firmware aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware csrb31024_firmware fastconnect_6…
|
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33051
|
2024-09-5 02:18 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312736
|
5.5 |
MEDIUM
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-28044
|
2024-09-5 02:12 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312737
|
5.4 |
MEDIUM
Network
|
easy_test_online_learning_and_testing_platform_project
|
easy_test_online_learning_and_testing_platform
|
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8328
|
2024-09-5 02:11 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312738
|
8.8 |
HIGH
Network
|
easy_test_online_learning_and_testing_platform_project
|
easy_test_online_learning_and_testing_platform
|
Easy test
Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbit…
|
CWE-89
SQL Injection
|
CVE-2024-8327
|
2024-09-5 02:11 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312739
|
5.5 |
MEDIUM
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-38382
|
2024-09-5 02:10 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312740
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8017_firmware aqt1000_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware msm8108_firmwa…
|
Memory corruption when Alternative Frequency offset value is set to 255.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-33042
|
2024-09-5 02:08 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312741
|
7.8 |
HIGH
Local
|
qualcomm
|
fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware qcm5430_firmware qcm6490_firmware qcs5430_firmware qcs6490_firmware video_collaboration_vc3_firmware…
|
Memory corruption when the captureRead QDCM command is invoked from user-space.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33047
|
2024-09-5 02:07 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312742
|
7.5 |
HIGH
Network
|
qualcomm
|
ar8035_firmware ar9380_firmware csr8811_firmware csra6620_firmware csra6640_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_…
|
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33050
|
2024-09-5 02:07 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312743
|
7.8 |
HIGH
Local
|
qualcomm
|
fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware qcm5430_firmware qcm6490_firmware qcm8550_firmware qcs5430_firmware qcs6490_firmware qcs8550_firm…
|
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-33054
|
2024-09-5 02:06 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312744
|
7.8 |
HIGH
Local
|
qualcomm
|
315_5g_iot_firmware aqt1000_firmware ar8031_firmware ar8035_firmware c-v2x_9150_firmware csra6620_firmware csra6640_firmware fastconnect_6200_firmware fastconnect_6700_firmwar…
|
Memory corruption when two threads try to map and unmap a single node simultaneously.
|
CWE-416
Use After Free
|
CVE-2024-33060
|
2024-09-5 02:06 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312745
|
7.5 |
HIGH
Network
|
qualcomm
|
ar8035_firmware csr8811_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_firmware immersive_home_214_firmware immersive_home_2…
|
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33057
|
2024-09-5 02:06 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312746
|
7.8 |
HIGH
Local
|
qualcomm
|
ar8035_firmware c-v2x_9150_firmware fastconnect_7800_firmware qca6574a_firmware qca6584au_firmware qca6595au_firmware qca6696_firmware qca6698aq_firmware qca8081_firmware q…
|
Memory corruption while processing concurrent IOCTL calls.
|
CWE-416
Use After Free
|
CVE-2024-38401
|
2024-09-5 02:05 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312747
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a…
|
NVD-CWE-noinfo
|
CVE-2024-41162
|
2024-09-5 02:03 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312748
|
7.8 |
HIGH
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-38386
|
2024-09-5 01:56 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312749
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId val…
|
CWE-346
Origin Validation Error
|
CVE-2024-41926
|
2024-09-5 01:55 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312750
|
6.5 |
MEDIUM
Network
|
misp
|
misp
|
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
|
CWE-863
Incorrect Authorization
|
CVE-2024-45509
|
2024-09-5 01:45 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|