|
248851
|
- |
|
-
|
-
|
A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con…
|
CWE-20
Improper Input Validation
|
CVE-2024-20484
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248852
|
- |
|
-
|
-
|
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions.
This…
|
-
|
CVE-2024-20476
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248853
|
- |
|
-
|
-
|
A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive inform…
|
CWE-200
Information Exposure
|
CVE-2024-20457
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248854
|
- |
|
-
|
-
|
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive info…
|
CWE-200
Information Exposure
|
CVE-2024-20445
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248855
|
- |
|
-
|
-
|
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, rem…
|
CWE-77
Command Injection
|
CVE-2024-20418
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248856
|
- |
|
-
|
-
|
A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should be blocked to the management in…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2024-20371
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248857
|
- |
|
-
|
-
|
Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-10827
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248858
|
- |
|
-
|
-
|
Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security s…
|
-
|
CVE-2024-10826
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248859
|
7.5 |
HIGH
Network
|
-
|
-
|
A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication k…
|
CWE-200
Information Exposure
|
CVE-2024-6861
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248860
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript …
|
CWE-79
Cross-site Scripting
|
CVE-2024-35146
|
2024-11-7 03:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|