|
256271
|
7.1 |
HIGH
Network
|
pepperl-fuchs
|
icdm-rx\/tcp_socketserver_firmware profinet_firmware profinet\/modbus_firmware modbus_router_firmware modbus_server_firmware modbus_tcp_firmware ethernet\/ip_firmware eip\/modbus…
|
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
|
CWE-79
Cross-site Scripting
|
CVE-2024-5849
|
2024-08-22 22:39 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256272
|
7.1 |
HIGH
Network
|
pepperl-fuchs
|
icdm-rx\/tcp_socketserver_firmware profinet_firmware profinet\/modbus_firmware modbus_router_firmware modbus_server_firmware modbus_tcp_firmware ethernet\/ip_firmware eip\/modbus…
|
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
|
CWE-79
Cross-site Scripting
|
CVE-2024-38502
|
2024-08-22 22:35 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256273
|
6.1 |
MEDIUM
Network
|
pepperl-fuchs
|
icdm-rx\/tcp_socketserver_firmware profinet_firmware profinet\/modbus_firmware modbus_router_firmware modbus_server_firmware modbus_tcp_firmware ethernet\/ip_firmware eip\/modbus…
|
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
|
CWE-79
Cross-site Scripting
|
CVE-2024-38501
|
2024-08-22 22:34 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256274
|
7.2 |
HIGH
Network
|
elastic
|
kibana
|
A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototyp…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2024-37287
|
2024-08-22 22:33 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256275
|
7.5 |
HIGH
Network
|
ibm
|
openbmc
|
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-35124
|
2024-08-22 22:31 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256276
|
7.5 |
HIGH
Network
|
ibm
|
common_licensing
|
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.
|
CWE-521
Weak Password Requirements
|
CVE-2024-40697
|
2024-08-22 22:27 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256277
|
2.7 |
LOW
Network
|
mainwww
|
mwcms
|
A vulnerability was found in Fujian mwcms 1.0.0. It has been rated as critical. Affected by this issue is the function uploadimage of the file /uploadfile.html. The manipulation of the argument upfil…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7706
|
2024-08-22 22:26 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256278
|
9.8 |
CRITICAL
Network
|
tenda
|
fh1206_firmware
|
A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function formSafeEmailFilter of the file /goform/SafeEmailFilter of the component HTTP …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7707
|
2024-08-22 22:23 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256279
|
- |
|
-
|
-
|
Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.
|
CWE-862
Missing Authorization
|
CVE-2024-43331
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256280
|
- |
|
-
|
-
|
Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-39576
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|