4.3

CVSS3.1

CVE-2024-20497 - Cisco Expressway Edge Improper Authorization Vulnerability

A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is due to inadequate authorization checks for Mobile and Remote Access (MRA) users. An attacker could exploit this vulneraโ€ฆ

๐Ÿ“… Published: Sept. 4, 2024, 4:29 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 11:51 p.m.

5.5

CVSS3.1

CVE-2024-20503 - Cisco Duo Epic for Hyperdrive Information Disclosure Vulnerability

A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key. A low-privileged attacker could exploit this vulnerabilityโ€ฆ

๐Ÿ“… Published: Sept. 4, 2024, 4:29 p.m. ๐Ÿ”„ Last Modified: Sept. 13, 2024, 7:24 p.m.

6

CVSS3.1

CVE-2024-20469 - Cisco Identity Services Engine Command Injection Vulnerability

A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid Administrโ€ฆ

๐Ÿ“… Published: Sept. 4, 2024, 4:28 p.m. ๐Ÿ”„ Last Modified: Sept. 25, 2025, 8:26 p.m.

7.5

CVSS3.1

CVE-2024-20440 -

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected deโ€ฆ

๐Ÿ“… Published: Sept. 4, 2024, 4:28 p.m. ๐Ÿ”„ Last Modified: April 1, 2025, 9:47 p.m.

9.8

CVSS3.1

CVE-2024-20439 -

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker couldโ€ฆ

๐Ÿ“… Published: Sept. 4, 2024, 4:28 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 1:59 p.m.

3.6

CVSS3.1

CVE-2024-45314 - Flask-AppBuilder login form allows browser to cache sensitive fields

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If uโ€ฆ

๐Ÿ“… Published: Sept. 4, 2024, 4:08 p.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:14 p.m.

9.1

CVSS3.1

CVE-2024-45053 - Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine

Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitization or rendering environment restrictions, allowing for Server-Side Template Injection that grants Remote Code Executiโ€ฆ

๐Ÿ“… Published: Sept. 4, 2024, 4:04 p.m. ๐Ÿ”„ Last Modified: Sept. 6, 2024, 6:20 p.m.

6.5

CVSS3.1

CVE-2024-45074 - IBM webMethods Integration directory traversal

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

๐Ÿ“… Published: Sept. 4, 2024, 4:02 p.m. ๐Ÿ”„ Last Modified: Sept. 6, 2024, 4:45 p.m.

8.8

CVSS3.1

CVE-2024-45075 - IBM webMethods Integration privilege escalation

IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.

๐Ÿ“… Published: Sept. 4, 2024, 4:01 p.m. ๐Ÿ”„ Last Modified: Sept. 29, 2025, 6:15 p.m.

9.9

CVSS3.1

CVE-2024-45076 - IBM webMethods Integration code execution

IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.

๐Ÿ“… Published: Sept. 4, 2024, 3:59 p.m. ๐Ÿ”„ Last Modified: Sept. 6, 2024, 4:44 p.m.
Total resulsts: 349182
Page 8657 of 34,919
ยซ previous page ยป next page
Filters