Show filters
3,123 Total Results
Displaying 131-140 of 3,123
Sort by:
Attacker Value
Unknown
CVE-2024-23957
Disclosure Date: September 28, 2024 (last updated October 04, 2024)
Autel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DLB_HostHeartBeat handler of the DLB protocol implementation. When parsing an AES key, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.
Was ZDI-CAN-23241
0
Attacker Value
Unknown
CVE-2024-9301
Disclosure Date: September 27, 2024 (last updated October 08, 2024)
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
0
Attacker Value
Unknown
CVE-2024-7400
Disclosure Date: September 27, 2024 (last updated September 27, 2024)
The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.
0
Attacker Value
Unknown
CVE-2023-52950
Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors.
0
Attacker Value
Unknown
CVE-2023-52949
Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
0
Attacker Value
Unknown
CVE-2023-52948
Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
0
Attacker Value
Unknown
CVE-2023-52947
Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be affected by the logout.
0
Attacker Value
Unknown
CVE-2024-43201
Disclosure Date: September 23, 2024 (last updated October 01, 2024)
The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024-07-25) fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information.
0
Attacker Value
Unknown
CVE-2024-43188
Disclosure Date: September 18, 2024 (last updated September 29, 2024)
IBM Business Automation Workflow
22.0.2, 23.0.1, 23.0.2, and 24.0.0
could allow a privileged user to perform unauthorized activities due to improper client side validation.
0
Attacker Value
Unknown
CVE-2024-43460
Disclosure Date: September 17, 2024 (last updated February 26, 2025)
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
0