81
|
7.6 |
HIGH
Network
|
-
|
-
|
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod.…
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-45497
|
2024-12-31 12:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
82
|
8.8 |
HIGH
Network
|
-
|
-
|
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access ce…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-13040
|
2024-12-31 11:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
83
|
8.8 |
HIGH
Network
|
-
|
-
|
The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed …
New
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2024-12839
|
2024-12-31 11:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
84
|
8.8 |
HIGH
Network
|
-
|
-
|
The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted request…
New
|
CWE-302
Authentication Bypass by Assumed-Immutable Data
|
CVE-2024-12838
|
2024-12-31 11:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
85
|
- |
|
-
|
-
|
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewal…
Update
|
-
|
CVE-2024-3393
|
2024-12-31 11:00 |
2024-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
86
|
- |
|
-
|
-
|
An issue exists in SoftIron HyperCloud
where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backend software-defined…
New
|
-
|
CVE-2024-13058
|
2024-12-31 07:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
87
|
- |
|
-
|
-
|
Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2024-13051
|
2024-12-31 06:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
88
|
- |
|
-
|
-
|
Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2024-13050
|
2024-12-31 06:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
89
|
- |
|
-
|
-
|
Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellu…
New
|
CWE-843
Type Confusion
|
CVE-2024-13049
|
2024-12-31 06:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
90
|
- |
|
-
|
-
|
Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2024-13048
|
2024-12-31 06:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|