Show filters
728 Total Results
Displaying 31-40 of 728
Sort by:
Attacker Value
Unknown

CVE-2024-39948

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
Attacker Value
Unknown

CVE-2024-39947

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.
Attacker Value
Unknown

CVE-2024-39946

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing device initialization.
Attacker Value
Unknown

CVE-2024-39945

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.  After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.
Attacker Value
Unknown

CVE-2024-39944

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
Attacker Value
Unknown

CVE-2024-40895

Disclosure Date: July 30, 2024 (last updated July 30, 2024)
FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executable file path is set to a batch file (.bat) or command file (.cmd) extension.
0
Attacker Value
Unknown

CVE-2024-40872

Disclosure Date: July 25, 2024 (last updated July 26, 2024)
There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to version 13.07. Attackers with local access and valid desktop user credentials can elevate their privilege to system level by passing invalid address data to the vulnerable component. This could be used to manipulate process tokens to elevate the privilege of a normal process to System. The scope is changed, the impact to system confidentiality and integrity is high, the impact to the availability of the effected component is none.
0
Attacker Value
Unknown

CVE-2024-6398

Disclosure Date: July 15, 2024 (last updated July 20, 2024)
An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is low, because other recommended default security policies such as URL categorization and GTI are in place in most policies to block access to uncategorized/high risk websites. Any information disclosed depends on how the customers have customized the block pages.
Attacker Value
Unknown

CVE-2024-39326

Disclosure Date: July 02, 2024 (last updated July 03, 2024)
SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectname}/skills/{skillname}/video` (and probably others) is open to a cross-site request forgery (CSRF) vulnerability. Due to the endpoint being CSRFable e.g POST request, supports a content type that can be exploited (multipart file upload), makes a state change and has no CSRF mitigations in place (samesite flag, CSRF token). It is possible to perform a CSRF attack against a logged in admin account, allowing an attacker that can target a logged in admin of Skills Service to modify the videos, captions, and text of the skill. Version 2.12.6 contains a patch for this issue.
0
Attacker Value
Unknown

CVE-2024-6127

Disclosure Date: June 27, 2024 (last updated June 28, 2024)
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.
0