1141
|
- |
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator.
This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0.
The deprecated org.apache.lucene.replicat…
|
-
|
CVE-2024-45772
|
2024-09-30 18:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1142
|
- |
|
-
|
-
|
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifyin…
|
-
|
CVE-2024-9329
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1143
|
7.2 |
HIGH
Network
|
-
|
-
|
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and ob…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-8459
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1144
|
8.8 |
HIGH
Network
|
-
|
-
|
Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malici…
|
-
|
CVE-2024-8458
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1145
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8457
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1146
|
9.8 |
CRITICAL
Network
-
|
-
|
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and sy…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-8456
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1147
|
8.1 |
HIGH
Network
|
-
|
-
|
The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user p…
|
CWE-261
Weak Encoding for Password
|
CVE-2024-8455
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1148
|
5.3 |
MEDIUM
Network
-
|
-
|
The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote…
|
CWE-476 CWE-400
NULL Pointer Dereference Uncontrolled Resource Consumption
|
CVE-2024-8454
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1149
|
- |
|
-
|
-
|
Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files …
|
CWE-328 CWE-759
Use of Weak Hash Use of a One-Way Hash without a Salt
|
CVE-2024-8453
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1150
|
- |
|
-
|
-
|
A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allow…
|
CWE-29
Path Traversal: '\..\filename'
|
CVE-2024-6394
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|