|
313141
|
9.8 |
CRITICAL
Network
|
alientechnology
|
alr-f800_firmware
|
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the file /var/www/cmd.php. The manipulation of the arg…
|
CWE-285
Improper Authorization
|
CVE-2024-7578
|
2024-08-29 03:27 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313142
|
8.8 |
HIGH
Network
|
alientechnology
|
alr-f800_firmware
|
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen of the file /var/www/cgi-bin/upgrade.c…
|
CWE-78
OS Command
|
CVE-2024-7579
|
2024-08-29 03:26 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313143
|
7.8 |
HIGH
Local
|
okta
|
verify
|
Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-7061
|
2024-08-29 03:25 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313144
|
5.4 |
MEDIUM
Network
|
opentext
|
alm_octane
|
Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote code executi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6361
|
2024-08-29 03:17 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313145
|
5.4 |
MEDIUM
Network
|
zephyr-one
|
zephyr_project_manager
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43915
|
2024-08-29 02:44 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313146
|
7.5 |
HIGH
Network
|
yanzhenjie
|
andserver
|
AndServer 2.1.12 is vulnerable to Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2024-41310
|
2024-08-29 02:42 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313147
|
- |
|
-
|
-
|
An SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve remote code execution via an HTTP POST /TermInput request.
|
-
|
CVE-2024-34087
|
2024-08-29 01:35 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313148
|
- |
|
-
|
-
|
An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.
|
-
|
CVE-2024-42845
|
2024-08-29 01:35 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313149
|
9.8 |
CRITICAL
Network
|
hitachienergy
|
microscada_x_sys600
|
The product exposes a service that is intended for local only to
all network interfaces without any authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-7940
|
2024-08-29 01:24 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313150
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
|
-
|
CVE-2024-35326
|
2024-08-29 01:15 |
2024-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|