|
312381
|
- |
|
-
|
-
|
Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploit…
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2024-44113
|
2024-09-10 12:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312382
|
- |
|
-
|
-
|
The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploi…
|
-
|
CVE-2024-42380
|
2024-09-10 12:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312383
|
- |
|
-
|
-
|
Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected Cross-Site Scripting (XSS) v…
|
CWE-79
Cross-site Scripting
|
CVE-2024-42378
|
2024-09-10 12:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312384
|
- |
|
-
|
-
|
The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to identify usernames and access information about ta…
|
CWE-862
Missing Authorization
|
CVE-2024-42371
|
2024-09-10 12:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312385
|
- |
|
-
|
-
|
Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker ca…
|
CWE-359 CWE-862
Exposure of Private Personal Information to an Unauthorized Actor Missing Authorization
|
CVE-2024-41729
|
2024-09-10 12:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312386
|
9.8 |
CRITICAL
Network
|
-
|
-
|
**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15…
|
CWE-78
OS Command
|
CVE-2024-6342
|
2024-09-10 11:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312387
|
- |
|
-
|
-
|
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
|
-
|
CVE-2024-44849
|
2024-09-10 05:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312388
|
- |
|
-
|
-
|
D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Re…
|
-
|
CVE-2024-44335
|
2024-09-10 05:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312389
|
- |
|
-
|
-
|
D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution…
|
-
|
CVE-2024-44334
|
2024-09-10 05:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312390
|
- |
|
-
|
-
|
A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some f…
|
CWE-285
Improper Authorization
|
CVE-2024-8509
|
2024-09-10 04:15 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|