Show filters
317,036 Total Results
Displaying 11-20 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-41114

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 430 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 435, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.
0
Attacker Value
Unknown

CVE-2024-4786

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on.
Attacker Value
Unknown

CVE-2024-41113

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 383 or line 390 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 395, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.
0
Attacker Value
Unknown

CVE-2024-41112

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 380, leading to remote code execution. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.
0
Attacker Value
Unknown

CVE-2024-40117

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server.
0
Attacker Value
Unknown

CVE-2024-40116

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files.
0
Attacker Value
Unknown

CVE-2024-38512

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
Attacker Value
Unknown

CVE-2024-38511

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
Attacker Value
Unknown

CVE-2024-38510

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
Attacker Value
Unknown

CVE-2024-38509

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to execute arbitrary code via a specially crafted IPMI command.