2.5
CVE-2024-45835 - Insufficient Electron Fuses Configuration
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
3.7
CVE-2024-39772 - Silent Desktop Screenshot Capture
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
9.8
CVE-2024-22399 - Apache Seata: Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata Server
Deserialization of Untrusted Data vulnerability in Apache Seata.Β When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on the Seata private protoβ¦
3.3
CVE-2024-46970 -
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
9.1
CVE-2024-7387 - Openshift/builder: path traversal allows command injection in privileged buildcontainer using dockeβ¦
A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the βDockerβ strategy, executable files inside the privileged build container β¦
9.9
CVE-2024-45496 - Openshift-controller-manager: elevated build pods can lead to node compromise in openshift
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attackβ¦
5.3
CVE-2024-1578 - Multiple MiCard PLUS card reader dropped characters
The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result in characters randomly being dropped from some ID card reads, which would result in the wrong ID card number being assigned during ID card self-registration anβ¦
9.8
CVE-2024-45698 - D-Link WiFi router - OS Command Injection
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.
9.8
CVE-2024-45697 - D-Link WiFi router - Hidden Functionality
Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials.
8.8
CVE-2024-45696 - D-Link WiFi router - Hidden Functionality
Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this method can only be accessed from within the saβ¦