481
|
- |
|
-
|
-
|
The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify fo…
Update
|
-
|
CVE-2024-23674
|
2024-11-7 03:35 |
2024-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
482
|
3.3 |
LOW
Local
|
google
|
android
|
In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no…
Update
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2023-21246
|
2024-11-7 03:35 |
2023-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
483
|
6.5 |
MEDIUM
Adjacent
|
elecom
|
wrc-1167ghbk-s_firmware wrc-1167gebk-s_firmware wrc-1167febk-s_firmware wrc-1167ghbk3-a_firmware wrc-1167febk-a_firmware
|
ELECOM wireless LAN routers are vulnerable to sensitive information exposure, which allows a network-adjacent unauthorized attacker to obtain sensitive information. Affected products and versions are…
Update
|
NVD-CWE-noinfo
|
CVE-2023-37563
|
2024-11-7 03:35 |
2023-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
484
|
9.8 |
CRITICAL
Network
nginxui
|
nginx_ui
|
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, cau…
Update
|
NVD-CWE-noinfo
|
CVE-2024-49368
|
2024-11-7 03:28 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
485
|
- |
|
-
|
-
|
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface.
This vulnerability …
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-20539
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
486
|
- |
|
-
|
-
|
A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an authenticated, remote attacker with low privileges to conduct a s…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-20540
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
487
|
- |
|
-
|
-
|
A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability exis…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-20538
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
488
|
- |
|
-
|
-
|
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions.
This …
New
|
CWE-863
Incorrect Authorization
|
CVE-2024-20537
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
489
|
- |
|
-
|
-
|
A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to …
New
|
CWE-89
SQL Injection
|
CVE-2024-20536
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
490
|
- |
|
-
|
-
|
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need …
New
|
CWE-22
Path Traversal
|
CVE-2024-20532
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|