Show filters
728 Total Results
Displaying 31-40 of 728
Sort by:
Attacker Value
Unknown
CVE-2024-39948
Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
0
Attacker Value
Unknown
CVE-2024-39947
Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.
0
Attacker Value
Unknown
CVE-2024-39946
Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing device initialization.
0
Attacker Value
Unknown
CVE-2024-39945
Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products. After
obtaining the administrator's username and password, the attacker can send a
carefully crafted data packet to the interface with vulnerabilities, causing
the device to crash.
0
Attacker Value
Unknown
CVE-2024-39944
Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.Attackers
can send carefully crafted data packets to the interface with vulnerabilities,
causing the device to crash.
0
Attacker Value
Unknown
CVE-2024-40895
Disclosure Date: July 30, 2024 (last updated July 30, 2024)
FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executable file path is set to a batch file (.bat) or command file (.cmd) extension.
0
Attacker Value
Unknown
CVE-2024-40872
Disclosure Date: July 25, 2024 (last updated July 26, 2024)
There is an elevation of privilege vulnerability in server
and client components of Absolute Secure Access prior to version 13.07.
Attackers with local access and valid desktop user credentials can elevate
their privilege to system level by passing invalid address data to the vulnerable
component. This could be used to
manipulate process tokens to elevate the privilege of a normal process to
System. The scope is changed, the impact to system confidentiality and
integrity is high, the impact to the availability of the effected component is
none.
0
Attacker Value
Unknown
CVE-2024-6398
Disclosure Date: July 15, 2024 (last updated July 20, 2024)
An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is low, because other recommended default security policies such as URL categorization and GTI are in place in most policies to block access to uncategorized/high risk websites. Any information disclosed depends on how the customers have customized the block pages.
0
Attacker Value
Unknown
CVE-2024-39326
Disclosure Date: July 02, 2024 (last updated July 03, 2024)
SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint
`/admin/projects/{projectname}/skills/{skillname}/video` (and probably others) is open to a cross-site request forgery (CSRF) vulnerability. Due to the endpoint being CSRFable e.g POST request, supports a content type that can be exploited (multipart file upload), makes a state change and has no CSRF mitigations in place (samesite flag, CSRF token). It is possible to perform a CSRF attack against a logged in admin account, allowing an attacker that can target a logged in admin of Skills Service to modify the videos, captions, and text of the skill. Version 2.12.6 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2024-6127
Disclosure Date: June 27, 2024 (last updated June 28, 2024)
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.
0