Show filters
329,450 Total Results
Displaying 2,611-2,620 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-46548

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.
0
Attacker Value
Unknown

CVE-2024-46540

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.
0
Attacker Value
Unknown

CVE-2024-45993

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.
0
Attacker Value
Unknown

CVE-2024-47532

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require access to the module string, it can remove it from RestrictedPython.Utilities.utility_builtins or otherwise do not make it available in the restricted execution environment.
0
Attacker Value
Unknown

CVE-2024-47531

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the compromise of users' devices or data. This vulnerability is fixed in 4.89.
0
Attacker Value
Unknown

CVE-2024-47530

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users by redirecting them to malicious page. /login API endpoint is vulnerable to open redirect attack via next parameter due to absence of sanitization logic. Additionally, due to lack of scheme validation, HTTPS Downgrade Attack can be performed on the users. This vulnerability is fixed in 4.89.
0
Attacker Value
Unknown

CVE-2024-47178

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.
0
Attacker Value
Unknown

CVE-2024-47067

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0.
0
Attacker Value
Unknown

CVE-2024-46869

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: Allocate memory for driver private data Fix driver not allocating memory for struct btintel_data which is used to store internal data.
0
Attacker Value
Unknown

CVE-2024-46510

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface
0