Show filters
3,391 Total Results
Displaying 91-100 of 3,391
Sort by:
Attacker Value
Unknown

CVE-2023-29115

Disclosure Date: November 05, 2024 (last updated November 09, 2024)
In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).
Attacker Value
Unknown

CVE-2024-47827

Disclosure Date: October 28, 2024 (last updated November 06, 2024)
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to a race condition in a global variable in 3.6.0-rc1, the argo workflows controller can be made to crash on-command by any user with access to execute a workflow. This vulnerability is fixed in 3.6.0-rc2.
Attacker Value
Unknown

CVE-2024-47481

Disclosure Date: October 25, 2024 (last updated October 31, 2024)
Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Denial of service.
Attacker Value
Unknown

CVE-2024-10194

Disclosure Date: October 20, 2024 (last updated October 24, 2024)
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been classified as critical. Affected is the function Goto_chidx of the file login.cgi of the component Front-End Authentication Page. The manipulation of the argument wlanUrl leads to stack-based buffer overflow. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-49386

Disclosure Date: October 17, 2024 (last updated October 19, 2024)
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
Attacker Value
Unknown

CVE-2024-21257

Disclosure Date: October 15, 2024 (last updated November 07, 2024)
Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion BI+ executes to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion BI+ accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).
Attacker Value
Unknown

CVE-2024-49384

Disclosure Date: October 15, 2024 (last updated October 17, 2024)
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Attacker Value
Unknown

CVE-2024-49383

Disclosure Date: October 15, 2024 (last updated October 17, 2024)
Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Attacker Value
Unknown

CVE-2024-49382

Disclosure Date: October 15, 2024 (last updated October 17, 2024)
Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Attacker Value
Unknown

CVE-2024-35520

Disclosure Date: October 14, 2024 (last updated October 17, 2024)
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.