Show filters
724 Total Results
Displaying 11-20 of 724
Sort by:
Attacker Value
Unknown

CVE-2024-11120

Disclosure Date: November 15, 2024 (last updated December 21, 2024)
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
Attacker Value
Unknown

CVE-2024-49560

Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
Attacker Value
Unknown

CVE-2024-49558

Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Attacker Value
Unknown

CVE-2024-49557

Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Attacker Value
Unknown

CVE-2024-48838

Disclosure Date: November 12, 2024 (last updated November 16, 2024)
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Attacker Value
Unknown

CVE-2024-48837

Disclosure Date: November 12, 2024 (last updated November 19, 2024)
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution
Attacker Value
Unknown

CVE-2024-8882

Disclosure Date: November 12, 2024 (last updated November 15, 2024)
A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL.
Attacker Value
Unknown

CVE-2024-8881

Disclosure Date: November 12, 2024 (last updated November 15, 2024)
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted HTTP request.
Attacker Value
Unknown

CVE-2024-43689

Disclosure Date: October 21, 2024 (last updated November 26, 2024)
Stack-based buffer overflow vulnerability exists in ELECOM wireless access points. By processing a specially crafted HTTP request, arbitrary code may be executed.
Attacker Value
Unknown

CVE-2024-39577

Disclosure Date: September 26, 2024 (last updated January 05, 2025)
Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability leading to code execution.