|
307141
|
- |
|
-
|
-
|
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-38365. Reason: This record is a duplicate of CVE-2024-38365. Notes: All CVE users should reference CVE-2024-38365 instead of this rec…
|
-
|
CVE-2024-36051
|
2024-10-12 06:15 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307142
|
- |
|
-
|
-
|
Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker with local access to potentially enab…
|
-
|
CVE-2024-47975
|
2024-10-12 05:15 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307143
|
4.3 |
MEDIUM
Network
|
siemens
|
sinec_security_monitor
|
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with a list of allowed valu…
|
NVD-CWE-Other
|
CVE-2024-47565
|
2024-10-12 05:05 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307144
|
5.3 |
MEDIUM
Network
|
siemens
|
sinec_security_monitor
|
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended…
|
CWE-22
Path Traversal
|
CVE-2024-47563
|
2024-10-12 05:05 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307145
|
8.8 |
HIGH
Local
|
siemens
|
sinec_security_monitor
|
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-cl…
|
CWE-77
Command Injection
|
CVE-2024-47562
|
2024-10-12 05:04 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307146
|
9.9 |
CRITICAL
Network
|
siemens
|
sinec_security_monitor
|
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command.
This…
|
CWE-88
Argument Injection
|
CVE-2024-47553
|
2024-10-12 05:04 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307147
|
5.4 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
|
CWE-79
Cross-site Scripting
|
CVE-2024-47951
|
2024-10-12 04:57 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307148
|
5.4 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
|
CWE-79
Cross-site Scripting
|
CVE-2024-47950
|
2024-10-12 04:57 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307149
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
|
CWE-22
Path Traversal
|
CVE-2024-47949
|
2024-10-12 04:57 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307150
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
|
CWE-22
Path Traversal
|
CVE-2024-47948
|
2024-10-12 04:56 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|