|
248301
|
- |
|
-
|
-
|
An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a remote attacker to obtain the session of an unauthe…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-11318
|
2024-11-19 02:11 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248302
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software Website Template allows SQL Injection.This issue affects Website Template: befo…
|
CWE-89
SQL Injection
|
CVE-2024-3370
|
2024-11-19 02:11 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248303
|
- |
|
-
|
-
|
Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via…
|
-
|
CVE-2024-11023
|
2024-11-19 02:11 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248304
|
8.4 |
HIGH
Local
|
-
|
-
|
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of s…
|
CWE-22
Path Traversal
|
CVE-2020-26071
|
2024-11-19 02:11 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248305
|
- |
|
-
|
-
|
OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Prior to version 6.1.9, the regex validation used to prevent Introspecti…
|
CWE-284
Improper Access Control
|
CVE-2024-37155
|
2024-11-19 02:11 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248306
|
7.1 |
HIGH
Network
|
-
|
-
|
A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-41974
|
2024-11-19 02:11 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248307
|
8.1 |
HIGH
Network
|
-
|
-
|
A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2024-41973
|
2024-11-19 02:11 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248308
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2024-41972
|
2024-11-19 02:11 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248309
|
8.1 |
HIGH
Network
|
-
|
-
|
A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.
|
CWE-22
Path Traversal
|
CVE-2024-41971
|
2024-11-19 02:11 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248310
|
5.7 |
MEDIUM
Network
|
-
|
-
|
A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-41970
|
2024-11-19 02:11 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|