1471
|
8.8 |
HIGH
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua…
|
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.
|
CWE-78
OS Command
|
CVE-2024-43386
|
2024-09-28 04:33 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1472
|
8.8 |
HIGH
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua…
|
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
|
CWE-78
OS Command
|
CVE-2024-43385
|
2024-09-28 04:33 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1473
|
8.8 |
HIGH
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua…
|
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
|
NVD-CWE-noinfo
|
CVE-2024-43388
|
2024-09-28 04:32 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1474
|
7.5 |
HIGH
Network
redhat cryptography.io couchbase
|
ansible_automation_platform enterprise_linux update_infrastructure cryptography couchbase_server
|
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confi…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2023-50782
|
2024-09-28 04:15 |
2024-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1475
|
7.5 |
HIGH
Network
zoom
|
virtual_desktop_infrastructure zoom
|
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.
|
NVD-CWE-noinfo
|
CVE-2023-39203
|
2024-09-28 04:15 |
2023-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1476
|
7.5 |
HIGH
Network
zoom
|
zoom
|
Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.
|
CWE-20
Improper Input Validation
|
CVE-2023-39208
|
2024-09-28 04:15 |
2023-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1477
|
7.8 |
HIGH
Local
|
zoom
|
rooms zoom
|
Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.
|
CWE-269
Improper Privilege Management
|
CVE-2023-39211
|
2024-09-28 04:15 |
2023-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1478
|
6.5 |
MEDIUM
Network
|
zoom
|
zoom
|
Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.
|
CWE-20
Improper Input Validation
|
CVE-2023-39209
|
2024-09-28 04:15 |
2023-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1479
|
6.5 |
MEDIUM
Network
|
zoom
|
zoom virtual_desktop_infrastructure rooms
|
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.
|
NVD-CWE-Other
|
CVE-2023-36535
|
2024-09-28 04:15 |
2023-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1480
|
7.1 |
HIGH
Local
|
moxa
|
mxview_one mxview_one_central_manager
|
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensit…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-6785
|
2024-09-28 03:59 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|