5.1

CVSS4.0

CVE-2024-47122 - Insecure Storage of Sensitive Information in goTenna Pro

In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows for complete decryption of keys stored on the EUD if physically compromised. This allows an attacker to decrypt all encrypted broadcast communications based on encryption keys…

πŸ“… Published: Sept. 26, 2024, 5:19 p.m. πŸ”„ Last Modified: Oct. 17, 2024, 6:15 p.m.

6

CVSS4.0

CVE-2024-47121 - Weak Passwords Requirements in goTenna Pro

The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past messages sent via encr…

πŸ“… Published: Sept. 26, 2024, 5:18 p.m. πŸ”„ Last Modified: May 2, 2025, 4:25 p.m.

4.3

CVSS3.1

CVE-2024-47170 - Agnai File Disclosure Vulnerability: JSON via Path Traversal

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unauthorized access to sensitive information and …

πŸ“… Published: Sept. 26, 2024, 5:16 p.m. πŸ”„ Last Modified: March 12, 2025, 9:16 p.m.

8.8

CVSS3.1

CVE-2024-47169 - Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to attacker-chosen locations on the server, including JavaScript, enabling the execution of commands within those files…

πŸ“… Published: Sept. 26, 2024, 5:11 p.m. πŸ”„ Last Modified: Oct. 30, 2024, 6:25 p.m.

6.4

CVSS3.1

CVE-2024-47075 - DOM Clobbering gadgets found in layui that lead to Cross-site Scripting

LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerability that can lead to Cross-site Scripting (XSS) on web pages where attacker-controlled HTML elements (e.g., `img` tags with unsanitized `name` attributes) are present. Version 2.9…

πŸ“… Published: Sept. 26, 2024, 5:08 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 2:11 p.m.

6

CVSS4.0

CVE-2024-45374 - goTenna Pro ATAK Plugin Weak Password Requirements

The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past messages sent …

πŸ“… Published: Sept. 26, 2024, 5:08 p.m. πŸ”„ Last Modified: March 12, 2025, 9:17 p.m.

7.1

CVSS3.1

CVE-2024-39577 -

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability leading to code e…

πŸ“… Published: Sept. 26, 2024, 5:06 p.m. πŸ”„ Last Modified: Nov. 25, 2024, 6:20 p.m.

4.4

CVSS3.1

CVE-2024-45042 - Ory Kratos's `highest_available` setting does not properly respect code + mfa credentials

Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a number of preconditions, the `highest_available` setting will incorrectly assume that the identity’s highest available AAL is `aal1` even though it really is `aal2`. This means t…

πŸ“… Published: Sept. 26, 2024, 5:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-37125 -

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could potentially exploit this vulnerability leading to a denial of service.

πŸ“… Published: Sept. 26, 2024, 5:01 p.m. πŸ”„ Last Modified: Nov. 25, 2024, 6:30 p.m.

2

CVSS4.0

CVE-2024-9203 - Enpass Password Manager sensitive information in memory

A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached locally. The complexity …

πŸ“… Published: Sept. 26, 2024, 5 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8464 of 34,919
Β« previous page Β» next page
Filters