3.3

CVSS3.1

CVE-2023-25189 -

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-46488 -

sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: Oct. 2, 2024, 4:21 p.m.

8.8

CVSS3.1

CVE-2024-46489 -

A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: Oct. 2, 2024, 4:24 p.m.

8

CVSS3.1

CVE-2024-46461 -

VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the…

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-44825 -

Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2024-45066 - Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Command Injection

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.

πŸ“… Published: Sept. 24, 2024, 11:51 p.m. πŸ”„ Last Modified: Oct. 1, 2024, 4:18 p.m.

10

CVSS4.0

CVE-2024-43693 - Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Command Injection

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.

πŸ“… Published: Sept. 24, 2024, 11:50 p.m. πŸ”„ Last Modified: Oct. 1, 2024, 5:17 p.m.

8.7

CVSS4.0

CVE-2024-45373 - Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Improper Privilege Management

Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.

πŸ“… Published: Sept. 24, 2024, 11:48 p.m. πŸ”„ Last Modified: Oct. 1, 2024, 4:13 p.m.

9.3

CVSS4.0

CVE-2024-43423 - Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Use of Hard-coded Password

The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

πŸ“… Published: Sept. 24, 2024, 11:47 p.m. πŸ”„ Last Modified: Oct. 1, 2024, 3:41 p.m.

9.3

CVSS4.0

CVE-2024-43692 - Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Authentication Bypass Using an Alternate Path o…

An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.

πŸ“… Published: Sept. 24, 2024, 11:46 p.m. πŸ”„ Last Modified: Oct. 1, 2024, 4:22 p.m.
Total resulsts: 349182
Page 8483 of 34,919
Β« previous page Β» next page
Filters