6.8
CVE-2024-40644 - gitoxide's gix-path can use a fake program files location
gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user accounts without administrative privileges to create new direβ¦
5.3
CVE-2024-40647 - Unintentional exposure of environment variables to subprocesses in sentry-sdk
sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocesses despite the `env={}` setting. In Python's `subprocess` calls, all environment variables are passed to subprocesses by default. However, if you specβ¦
9.6
CVE-2024-5619 - IDOR in PruvaSoft Informatics' Apinizer Management Console
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: before 2024.05.1.
5.4
CVE-2024-40648 - `UserIdentity::is_verified` not checking verification status of own user identity while performing β¦
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's own identity while performing the check and may as a result reβ¦
5.7
CVE-2023-40704 - Philips Vue PACS Use of Default Credentials
The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.
0.0
CVE-2023-40539 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
9.9
CVE-2024-5618 - Broken Access Control in PruvaSoft Informatics' Apinizer Management Console
Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Apinizer Management Console: before 2024.05.1.
0.0
CVE-2023-40223 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
0.0
CVE-2023-40159 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
7.1
CVE-2023-50304 - IBM Engineering Requirements Management DOORS XML external entity injection
IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 273335.