591
|
8.8 |
HIGH
Network
|
-
|
-
|
An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-11497
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
592
|
- |
|
-
|
-
|
An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addres…
New
|
CWE-346
Origin Validation Error
|
CVE-2023-46715
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
593
|
- |
|
-
|
-
|
A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-42786
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
594
|
- |
|
-
|
-
|
A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-42785
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
595
|
- |
|
-
|
-
|
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6…
New
|
CWE-78
OS Command
|
CVE-2023-37937
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
596
|
- |
|
-
|
-
|
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 al…
New
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2023-37936
|
2025-01-14 23:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
597
|
7.4 |
HIGH
Network
|
-
|
-
|
A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to by…
New
|
CWE-90
LDAP Injection
|
CVE-2024-56841
|
2025-01-14 20:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
598
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been identified in Industrial Edge Management OS (IEM-OS) (All versions). Affected components are vulnerable to reflected cross-site scripting (XSS) attacks. This could allow an a…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-45385
|
2025-01-14 20:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
599
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.80), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.…
New
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2024-53649
|
2025-01-14 20:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
600
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input san…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-12240
|
2025-01-14 20:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|