2541
|
7.0 |
HIGH
Local
|
nozominetworks
|
cmc guardian
|
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authe…
|
CWE-384
Session Fixation
|
CVE-2023-24477
|
2024-09-20 22:15 |
2023-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2542
|
5.5 |
MEDIUM
Local
|
samsung
|
exynos_980_firmware exynos_850_firmware exynos_1080_firmware exynos_1280_firmware exynos_1380_firmware exynos_1330_firmware exynos_1480_firmware exynos_w920_firmware exynos_w9…
|
An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_b…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-27365
|
2024-09-20 22:09 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2543
|
7.2 |
HIGH
Network
|
mailcow
|
mailcow\
|
mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated at…
|
NVD-CWE-noinfo
|
CVE-2024-41958
|
2024-09-20 21:58 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2544
|
8.8 |
HIGH
Network
|
nuxt
|
nuxt
|
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vul…
|
CWE-22
Path Traversal
|
CVE-2024-23657
|
2024-09-20 21:49 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2545
|
5.4 |
MEDIUM
Network
|
opensearch
|
observability
|
OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resourc…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-39900
|
2024-09-20 21:40 |
2024-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2546
|
5.4 |
MEDIUM
Network
|
opensearch
|
observability
|
OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant resou…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-39901
|
2024-09-20 21:33 |
2024-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2547
|
- |
|
-
|
-
|
A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via th…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-5998
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2548
|
- |
|
-
|
-
|
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Back…
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2024-8767
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2549
|
- |
|
-
|
-
|
Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer.
If a computer on which the affected product is installed receives a large number of UDP broadcast packets…
|
-
|
CVE-2024-8110
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2550
|
- |
|
-
|
-
|
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone cont…
|
CWE-269
Improper Privilege Management
|
CVE-2024-45496
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|