8.8
CVE-2024-20435 -
A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this β¦
10
CVE-2024-20419 -
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change proceβ¦
9.8
CVE-2024-20401 -
A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is due to improper handling of email attachments when file analβ¦
5.3
CVE-2024-6830 - SourceCodester Simple Inventory Management System Order action.php sql injection
A vulnerability, which was classified as critical, was found in SourceCodester Simple Inventory Management System 1.0. Affected is an unknown function of the file action.php of the component Order Handler. The manipulation of the argument order_id leads to sql injection. It is possible to launch thβ¦
9.3
CVE-2023-4976 - FlashBlade Authentication Mechanism Vulnerability
A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
5.9
CVE-2024-29120 - Apache StreamPark: Information leakage vulnerability
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc.Β Mβ¦
9
CVE-2024-6834 - Imperative Local Command Injection allows Activity Masking
A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints requiring an internal client certificate without any credentials. It could lead to managing components in tβ¦
5.9
CVE-2024-6833 - Zowe CLI Auto-Init Leaks Credentials Locally
A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.
9.6
CVE-2024-23471 - SolarWinds Access Rights Manager (ARM) CreateFile Directory Traversal Remote Code Execution Vulneraβ¦
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.
9.6
CVE-2024-23470 - SolarWinds Access Rights Manager (ARM) UserScriptHumster Exposed Dangerous Method Remote Command Exβ¦
The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and executables.