Show filters
326,768 Total Results
Displaying 1,321-1,330 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-47078

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet connection or proxied through a connected phone (i.e., via bluetooth). Prior to version 2.5.1, multiple weaknesses in the MQTT implementation allow for authentication and authorization bypasses resulting in unauthorized control of MQTT-connected nodes. Version 2.5.1 contains a patch.
Attacker Value
Unknown

CVE-2024-46600

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31
0
Attacker Value
Unknown

CVE-2024-46485

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate
0
Attacker Value
Unknown

CVE-2024-44825

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.
0
Attacker Value
Unknown

CVE-2023-25189

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.
0
Attacker Value
Unknown

CVE-2024-46461

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.
0
Attacker Value
Unknown

CVE-2024-43990

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8.
0
Attacker Value
Unknown

CVE-2024-43959

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themepoints Testimonials allows Reflected XSS.This issue affects Testimonials: from n/a through 3.0.8.
0
Attacker Value
Unknown

CVE-2024-43237

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in TaxoPress WordPress Tag Cloud Plugin – Tag Groups.This issue affects WordPress Tag Cloud Plugin – Tag Groups: from n/a through 2.0.3.
0
Attacker Value
Unknown

CVE-2024-30128

Disclosure Date: September 25, 2024 (last updated September 26, 2024)
HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information.
0