|
256461
|
9.8 |
CRITICAL
Network
|
dell
|
dns-120_firmware dnr-202l_firmware dns-315l_firmware dns-320_firmware dns-320l_firmware dns-320lw_firmware dns-321_firmware dnr-322l_firmware dns-323_firmware dns-325_firmw…
|
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, …
|
CWE-77
Command Injection
|
CVE-2024-7922
|
2024-08-21 01:20 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256462
|
7.5 |
HIGH
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the clea…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-38891
|
2024-08-21 01:19 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256463
|
8.8 |
HIGH
Network
|
linksys
|
e1500_firmware
|
A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root pri…
|
CWE-78
OS Command
|
CVE-2024-42633
|
2024-08-21 01:18 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256464
|
7.5 |
HIGH
Network
|
nissan-global
|
blind_spot_protection_sensor_ecu_firmware
|
Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2024-6348
|
2024-08-21 01:17 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256465
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the databas…
|
CWE-78
OS Command
|
CVE-2024-38887
|
2024-08-21 01:17 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256466
|
7.8 |
HIGH
Local
|
google
|
android
|
In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
|
CWE-416
Use After Free
|
CVE-2024-32927
|
2024-08-21 01:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256467
|
7.5 |
HIGH
Network
|
nepstech
|
ntpl-xpon1gfevn_firmware
|
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2024-42657
|
2024-08-21 01:13 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256468
|
5.9 |
MEDIUM
Network
|
google haxx
|
nest_mini_firmware libcurl
|
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services …
|
NVD-CWE-noinfo
|
CVE-2024-32928
|
2024-08-21 01:13 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256469
|
9.8 |
CRITICAL
Network
|
nepstech
|
ntpl-xpon1gfevn_firmware
|
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
|
NVD-CWE-noinfo
|
CVE-2024-42658
|
2024-08-21 01:12 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256470
|
5.4 |
MEDIUM
Network
|
xwiki
|
xwiki
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a pa…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43400
|
2024-08-21 01:10 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|