|
313321
|
7.5 |
HIGH
Network
|
nissan-global
|
blind_spot_protection_sensor_ecu_firmware
|
Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2024-6348
|
2024-08-21 01:17 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313322
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the databas…
|
CWE-78
OS Command
|
CVE-2024-38887
|
2024-08-21 01:17 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313323
|
7.8 |
HIGH
Local
|
google
|
android
|
In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
|
CWE-416
Use After Free
|
CVE-2024-32927
|
2024-08-21 01:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313324
|
7.5 |
HIGH
Network
|
nepstech
|
ntpl-xpon1gfevn_firmware
|
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2024-42657
|
2024-08-21 01:13 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313325
|
5.9 |
MEDIUM
Network
|
google haxx
|
nest_mini_firmware libcurl
|
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services …
|
NVD-CWE-noinfo
|
CVE-2024-32928
|
2024-08-21 01:13 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313326
|
9.8 |
CRITICAL
Network
|
nepstech
|
ntpl-xpon1gfevn_firmware
|
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
|
NVD-CWE-noinfo
|
CVE-2024-42658
|
2024-08-21 01:12 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313327
|
5.4 |
MEDIUM
Network
|
xwiki
|
xwiki
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a pa…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43400
|
2024-08-21 01:10 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313328
|
8.0 |
HIGH
Network
|
xwiki
|
xwiki
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a conten…
|
CWE-862
Missing Authorization
|
CVE-2024-43401
|
2024-08-21 01:09 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313329
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path travers…
|
CWE-22
Path Traversal
|
CVE-2024-7924
|
2024-08-21 01:07 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313330
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome …
|
NVD-CWE-noinfo
|
CVE-2024-7925
|
2024-08-21 01:06 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|