4.4

CVSS3.1

CVE-2024-6876 - Out-of-bounds read in OSCAT-Library

Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a crash of the affected service.

πŸ“… Published: Sept. 10, 2024, 3:08 p.m. πŸ”„ Last Modified: Oct. 1, 2024, 7:15 a.m.

6.4

CVSS3.1

CVE-2024-45393 - Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook de…

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of other users. For each delivery, this contains info…

πŸ“… Published: Sept. 10, 2024, 3:04 p.m. πŸ”„ Last Modified: Jan. 21, 2025, 2:33 p.m.

8.8

CVSS3.1

CVE-2024-45044 - Bareos's negative command ACLs can be circumvented by abbreviating commands

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes a command in bconsole using an abbreviation (i.e. "w" for "whoami") the ACL check did not apply to the full form (i.e. "whoami") but to the abbreviate…

πŸ“… Published: Sept. 10, 2024, 2:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-42423 -

Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized ac…

πŸ“… Published: Sept. 10, 2024, 2:55 p.m. πŸ”„ Last Modified: Sept. 20, 2024, 7:42 p.m.

5

CVSS3.1

CVE-2024-43800 - serve-static affected by template injection that can lead to XSS

serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.

πŸ“… Published: Sept. 10, 2024, 2:50 p.m. πŸ”„ Last Modified: Sept. 20, 2024, 5:36 p.m.

5

CVSS3.1

CVE-2024-43799 - send vulnerable to template injection that can lead to XSS

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

πŸ“… Published: Sept. 10, 2024, 2:45 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

4.6

CVSS3.1

CVE-2022-45856 -

An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientAndroid 6.4 all versio…

πŸ“… Published: Sept. 10, 2024, 2:37 p.m. πŸ”„ Last Modified: Sept. 26, 2024, 2:48 p.m.

5.5

CVSS3.1

CVE-2024-21753 -

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or …

πŸ“… Published: Sept. 10, 2024, 2:37 p.m. πŸ”„ Last Modified: Sept. 25, 2024, 6:36 p.m.

6.4

CVSS3.1

CVE-2024-31489 -

AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in…

πŸ“… Published: Sept. 10, 2024, 2:37 p.m. πŸ”„ Last Modified: Sept. 20, 2024, 7:41 p.m.

3.4

CVSS3.1

CVE-2024-36511 -

An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions when cookie security policy is enabled may allow a…

πŸ“… Published: Sept. 10, 2024, 2:37 p.m. πŸ”„ Last Modified: Sept. 20, 2024, 7:43 p.m.
Total resulsts: 349182
Page 8615 of 34,919
Β« previous page Β» next page
Filters