6.5
CVE-2024-11946 - iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Informatioβ¦
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update files on affected installations of iXsystems TrueNAS devices. Authentication is not required to expβ¦
8.8
CVE-2024-11944 - iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability
iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS devices. Authentication is not required to exploit this vulnerability. Thβ¦
7.4
CVE-2024-56800 - Firecrawl has SSRF Vulnerability via malicious scrape target
Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions prior to 1.1.1 contain a server-side request forgery (SSRF) vulnerability. The scraping engine could be exploited by crafting a malicious site that redirects to a local IP address. β¦
10
CVE-2024-56799 - Simofa Allows Unauthenticated Access to API Routes
Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.
6.9
CVE-2024-56801 - Tasklists has Blind SQL Injection in /ajax/reorder.php
Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.
5.5
CVE-2024-12754 - AnyDesk Link Following Information Disclosure Vulnerability
AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulneβ¦
7.8
CVE-2024-12836 - Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the taβ¦
7.8
CVE-2024-12835 - Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabiliβ¦
Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that tβ¦
7.8
CVE-2024-12834 - Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the taβ¦
7.9
CVE-2024-56734 - Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better Auth prior to v1.1.6, potentially allowing attackers to redirect users to malicious websites. This issue affects users relying on email β¦