9.8

CVSS3.1

CVE-2024-41117 - Remote code execution in streamlit geospatial in pages/10_🌍_Earth_Engine_Datasets.py

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 115 in `pages/10_🌍_Earth_Engine_Datasets.py` takes user input, which is later used in the `eval()` function on line 126, leading…

πŸ“… Published: July 26, 2024, 8:49 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

9.8

CVSS3.1

CVE-2024-41116 - Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py MODIS Ocean Color SMI optio…

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 1254 in `pages/1_πŸ“·_Timelapse.py` takes user input, which is later used in the `eval()` function on line 1345, leading to remote …

πŸ“… Published: July 26, 2024, 8:16 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

9.8

CVSS3.1

CVE-2024-41115 - Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py MODIS Ocean Color SMI optio…

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 488 in `pages/1_πŸ“·_Timelapse.py` takes user input, which is later used in the `eval()` function on line 493, leading to remote code …

πŸ“… Published: July 26, 2024, 8:13 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

9.8

CVSS3.1

CVE-2024-41114 - Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py MODIS Gap filled Land Surfa…

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 430 in `pages/1_πŸ“·_Timelapse.py` takes user input, which is later used in the `eval()` function on line 435, leading to remote code …

πŸ“… Published: July 26, 2024, 8:10 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

9.8

CVSS3.1

CVE-2024-41113 - Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py Any Earth Engine ImageColle…

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 383 or line 390 in `pages/1_πŸ“·_Timelapse.py` takes user input, which is later used in the `eval()` function on line 395, leading …

πŸ“… Published: July 26, 2024, 8:05 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

9.8

CVSS3.1

CVE-2024-41112 - Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py Any Earth Engine ImageColle…

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_πŸ“·_Timelapse.py` takes user input, which is later used in the `eval()` function on line 380, leading to remote code execution. Com…

πŸ“… Published: July 26, 2024, 8:01 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

2.8

CVSS3.1

CVE-2024-4786 -

An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on.

πŸ“… Published: July 26, 2024, 7:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-38512 -

A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.

πŸ“… Published: July 26, 2024, 7:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-38511 -

A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.

πŸ“… Published: July 26, 2024, 7:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-38510 -

A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.

πŸ“… Published: July 26, 2024, 7:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9046 of 34,919
Β« previous page Β» next page
Filters