9.8

CVSS3.0

CVE-2024-5826 - Remote Code Execution via Prompt Injection in vanna-ai/vanna

In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack of a sandbox when executing LLM-generated code, allowing an attacker to manipulate the code executed by the `exec` function in `src/vanna/base…

πŸ“… Published: June 27, 2024, 6:40 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

7.5

CVSS3.0

CVE-2024-5979 - Denial of Service via Invalid Argument in h2oai/h2o-3

In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial of service.

πŸ“… Published: June 27, 2024, 6:40 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

9.9

CVSS3.1

CVE-2024-3330 - Spotfire Remote Code Execution Vulnerability

Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from…

πŸ“… Published: June 27, 2024, 6:37 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:29 a.m.

6.5

CVSS3.1

CVE-2024-3017 - Denial of service in multi-protocol gateway - Zigbee + Thread

In a Silicon LabsΒ Β multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.

πŸ“… Published: June 27, 2024, 6:35 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 4:15 p.m.

8.4

CVSS3.1

CVE-2024-4578 - Privilege escalation in Arista Wireless Access Points

This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the β€œconfig” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require high permissions to exploit…

πŸ“… Published: June 27, 2024, 6:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

7.5

CVSS3.1

CVE-2023-38370 - IBM Security Access Manager Docker information disclosure

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

πŸ“… Published: June 27, 2024, 6:27 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

5.5

CVSS3.1

CVE-2023-38368 - IBM Security Access Manager Docker information disclosure

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls. IBM X-Force ID: 261195.

πŸ“… Published: June 27, 2024, 6:25 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

7.8

CVSS3.1

CVE-2023-30997 - IBM Security Access Manager Docker privilege escalation

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254638.

πŸ“… Published: June 27, 2024, 6:21 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

7.8

CVSS3.1

CVE-2023-30998 - IBM Security Access Manager Docker privilege escalation

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254649.

πŸ“… Published: June 27, 2024, 6:18 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2024-3043 - Zigbee co-ordinator realignment packet may lead to denial of service

An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial of service. This packet type is not useful in production and should be used only for PHY qualification.

πŸ“… Published: June 27, 2024, 6:17 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.
Total resulsts: 342654
Page 8661 of 34,266
Β« previous page Β» next page
Filters