Show filters
335,472 Total Results
Displaying 651-660 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-45505

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-41969

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.
Attacker Value
Unknown

CVE-2024-41968

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.
Attacker Value
Unknown

CVE-2024-41967

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.
Attacker Value
Unknown

CVE-2024-41151

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-49574

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
Attacker Value
Unknown

CVE-2024-22067

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
Attacker Value
Unknown

CVE-2024-11315

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Attacker Value
Unknown

CVE-2024-11314

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Attacker Value
Unknown

CVE-2024-11313

Disclosure Date: November 18, 2024 (last updated November 21, 2024)
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.