4.4

CVSS3.1

CVE-2024-20289 - Cisco NX-OS Software Command Injection Vulnerability

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system of an affected device.  This vulnerability is due to insufficient validation of arguments for a specific CLI comma…

📅 Published: Aug. 28, 2024, 4:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-7745 - Multi-Factor Authentication Bypass in Progress WS_FTP Server

In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.

📅 Published: Aug. 28, 2024, 4:31 p.m. 🔄 Last Modified: Sept. 4, 2024, 5:57 p.m.

4.3

CVSS3.1

CVE-2024-6053 - Improper access control in the clipboard synchronization feature

Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a meeting.

📅 Published: Aug. 28, 2024, 4:30 p.m. 🔄 Last Modified: Sept. 19, 2024, 5:22 p.m.

6.5

CVSS3.1

CVE-2024-7744 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP S…

In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.   An authenticated file download flaw h…

📅 Published: Aug. 28, 2024, 4:30 p.m. 🔄 Last Modified: Sept. 4, 2024, 5:57 p.m.

6.5

CVSS3.1

CVE-2024-20478 - Cisco Application Policy Infrastructure Controller App Privilege Escalation Vulnerability

A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges to install a modified software image, …

📅 Published: Aug. 28, 2024, 4:30 p.m. 🔄 Last Modified: Aug. 1, 2025, 3:26 p.m.

6.7

CVSS3.1

CVE-2024-20411 - Cisco NX-OS Bash Arbitrary Code Execution Vulnerability

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on an affected device. This vulnerability is due to insufficient security restrictions when executing commands from the Bash shell.…

📅 Published: Aug. 28, 2024, 4:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2024-20413 - Cisco NX-OS Bash Privilege Escalation Vulnerability

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device. This vulnerability is due to insufficient security restrictions when executing application arguments from th…

📅 Published: Aug. 28, 2024, 4:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-20279 - Cisco Application Policy Infrastructure Controller Unauthorized Policy Actions Vulnerability

A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system. This …

📅 Published: Aug. 28, 2024, 4:19 p.m. 🔄 Last Modified: Aug. 1, 2025, 3:26 p.m.

5.3

CVSS3.1

CVE-2024-8195 - Permalink Manager Lite <= 2.4.4 - Missing Authorization to Unauthenticated Sensitive Information Ex…

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and 'debug_redirect' functions in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to extr…

📅 Published: Aug. 28, 2024, 1:54 p.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

5.3

CVSS4.0

CVE-2024-6450 - Reflected XSS in HyperView Geoportal Toolkit

HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser.

📅 Published: Aug. 28, 2024, 11:50 a.m. 🔄 Last Modified: Jan. 9, 2025, 5:38 p.m.
Total resulsts: 349182
Page 8713 of 34,919
« previous page » next page
Filters