71
|
8.8 |
HIGH
Network
|
apache
|
airflow_sqoop_provider
|
Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, which makes it possible to implement RCE attacks via…
Update
|
CWE-20
Improper Input Validation
|
CVE-2023-27604
|
2024-09-28 04:35 |
2023-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
72
|
8.8 |
HIGH
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua…
|
A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.
Update
|
CWE-78
OS Command
|
CVE-2024-43387
|
2024-09-28 04:33 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
73
|
8.8 |
HIGH
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua…
|
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.
Update
|
CWE-78
OS Command
|
CVE-2024-43386
|
2024-09-28 04:33 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
74
|
8.8 |
HIGH
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua…
|
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
Update
|
CWE-78
OS Command
|
CVE-2024-43385
|
2024-09-28 04:33 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
75
|
8.8 |
HIGH
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua…
|
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
Update
|
NVD-CWE-noinfo
|
CVE-2024-43388
|
2024-09-28 04:32 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
76
|
- |
|
-
|
-
|
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
New
|
-
|
CVE-2024-9160
|
2024-09-28 04:15 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
77
|
7.5 |
HIGH
Network
redhat cryptography.io couchbase
|
ansible_automation_platform enterprise_linux update_infrastructure cryptography couchbase_server
|
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confi…
Update
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2023-50782
|
2024-09-28 04:15 |
2024-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
78
|
7.5 |
HIGH
Network
zoom
|
virtual_desktop_infrastructure zoom
|
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.
Update
|
NVD-CWE-noinfo
|
CVE-2023-39203
|
2024-09-28 04:15 |
2023-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
79
|
7.5 |
HIGH
Network
zoom
|
zoom
|
Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.
Update
|
CWE-20
Improper Input Validation
|
CVE-2023-39208
|
2024-09-28 04:15 |
2023-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
80
|
7.8 |
HIGH
Local
|
zoom
|
rooms zoom
|
Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.
Update
|
CWE-269
Improper Privilege Management
|
CVE-2023-39211
|
2024-09-28 04:15 |
2023-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|