|
311941
|
8.8 |
HIGH
Network
|
qnap
|
qts quts_hero
|
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a net…
|
CWE-78
OS Command
|
CVE-2024-21898
|
2024-09-11 22:35 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311942
|
5.4 |
MEDIUM
Network
|
qnap
|
qts quts_hero
|
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code…
|
CWE-79
Cross-site Scripting
|
CVE-2024-21897
|
2024-09-11 22:34 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311943
|
6.5 |
MEDIUM
Network
|
qnap
|
qts quts_hero
|
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to launch a denial-of-service (DoS) atta…
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-51368
|
2024-09-11 22:33 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311944
|
6.5 |
MEDIUM
Network
|
qnap
|
qts quts_hero
|
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expos…
|
CWE-22
Path Traversal
|
CVE-2023-51366
|
2024-09-11 22:32 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311945
|
4.8 |
MEDIUM
Network
|
qnap
|
qts quts_hero
|
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to inject malic…
|
CWE-79
Cross-site Scripting
|
CVE-2023-50366
|
2024-09-11 22:31 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311946
|
8.8 |
HIGH
Network
|
qnap
|
qts quts_hero
|
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a …
|
CWE-120 CWE-121
Classic Buffer Overflow Stack-based Buffer Overflow
|
CVE-2023-51367
|
2024-09-11 22:27 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311947
|
6.5 |
MEDIUM
Network
|
zoom
|
workplace workplace_desktop workplace_virtual_desktop_infrastructure rooms
|
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-39818
|
2024-09-11 22:27 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311948
|
6.5 |
MEDIUM
Network
|
terminalfour
|
terminalfour
|
A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-22217
|
2024-09-11 22:19 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311949
|
5.4 |
MEDIUM
Network
|
yogeshojha
|
rengine
|
reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when scanning a…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43381
|
2024-09-11 22:02 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311950
|
9.8 |
CRITICAL
Network
|
h3c
|
magic_b1st_firmware
|
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-42638
|
2024-09-11 21:53 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|