7.5
CVE-2024-40763 -
Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
6.9
CVE-2024-12228 - PHPGurukul Complaint Management System user-search.php sql injection
A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unknown function of the file /admin/user-search.php. The manipulation of the argument search leads to sql injection. It is possible to launch the attack remotely. The exploit has beenβ¦
6.8
CVE-2024-12227 - MSI Dragon Center IOCTL NTIOLib_X64.sys MmUnMapIoSpace null pointer dereference
A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the function MmUnMapIoSpace in the library NTIOLib_X64.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on thβ¦
9.3
CVE-2024-51555 - Force Change of Default Credentials
Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials.Β Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02
8.8
CVE-2024-51554 - off-by-one-error
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.Β Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
9.3
CVE-2024-51551 - Default Credentials
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.Β Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02
9.3
CVE-2024-51550 - Data Validation / Sanitization
Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.Β Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
9.3
CVE-2024-51549 - Absolute Path Traversal
Absolute File Traversal vulnerabilities allows access and modification of un-intended resources.Β Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
8.7
CVE-2024-51548 - Dangerous File Upload
Dangerous File Upload vulnerabilities allow upload of malicious scripts.Β Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
8.7
CVE-2024-51546 - Credentails Disclosure
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.Β Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02