2731
|
- |
|
-
|
-
|
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, r…
|
-
|
CVE-2024-20534
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2732
|
- |
|
-
|
-
|
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, r…
|
CWE-79
Cross-site Scripting
|
CVE-2024-20533
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2733
|
- |
|
-
|
-
|
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2024-20514
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2734
|
- |
|
-
|
-
|
A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con…
|
CWE-20
Improper Input Validation
|
CVE-2024-20484
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2735
|
- |
|
-
|
-
|
Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-10827
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2736
|
- |
|
-
|
-
|
Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security s…
|
-
|
CVE-2024-10826
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2737
|
- |
|
-
|
-
|
A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\…
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2024-10920
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2738
|
7.5 |
HIGH
Network
-
|
-
|
A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication k…
|
CWE-200
Information Exposure
|
CVE-2024-6861
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2739
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript …
|
CWE-79
Cross-site Scripting
|
CVE-2024-35146
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2740
|
- |
|
-
|
-
|
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Authentication method confusion allows logging in as the built-in root user fro…
|
-
|
CVE-2024-10082
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|