|
312231
|
9.0 |
CRITICAL
Network
|
microsoft
|
edge_chromium
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
|
CWE-843
Type Confusion
|
CVE-2024-38219
|
2024-08-29 23:45 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312232
|
5.4 |
MEDIUM
Network
|
ibm
|
aspera_shares
|
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574.
|
CWE-384
Session Fixation
|
CVE-2023-38018
|
2024-08-29 23:36 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312233
|
7.2 |
HIGH
Network
|
abinitio
|
authorization_gateway metadata_hub
|
An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration.
|
CWE-94
Code Injection
|
CVE-2024-37382
|
2024-08-29 23:29 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312234
|
5.3 |
MEDIUM
Network
|
dorsettcontrols
|
infoscan
|
Dorsett Controls InfoScan is vulnerable due to a leak of possible
sensitive information through the response headers and the rendered
JavaScript prior to user login.
|
NVD-CWE-noinfo
|
CVE-2024-42493
|
2024-08-29 23:24 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312235
|
7.5 |
HIGH
Network
|
dorsettcontrols
|
infoscan
|
Dorsett Controls Central Server update server has potential information
leaks with an unprotected file that contains passwords and API keys.
|
NVD-CWE-noinfo
|
CVE-2024-39287
|
2024-08-29 23:23 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312236
|
3.7 |
LOW
Network
|
dorsettcontrols
|
infoscan
|
The InfoScan client download page can be intercepted with a proxy, to
expose filenames located on the system, which could lead to additional
information exposure.
|
CWE-22
Path Traversal
|
CVE-2024-42408
|
2024-08-29 23:22 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312237
|
9.0 |
CRITICAL
Network
|
vrcx-team
|
vrcx
|
VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-permission and cross-site scripting via overlay notification can be combined to re…
|
CWE-79
Cross-site Scripting
|
CVE-2024-42366
|
2024-08-29 23:04 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312238
|
4.8 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete CMS team gave this a CVS…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7394
|
2024-08-29 22:41 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312239
|
9.8 |
CRITICAL
Network
|
havocframework
|
havoc
|
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-41570
|
2024-08-29 22:32 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312240
|
- |
|
-
|
-
|
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentia…
|
CWE-788
Access of Memory Location After End of Buffer
|
CVE-2024-38304
|
2024-08-29 22:25 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|