|
307301
|
4.3 |
MEDIUM
Network
|
adobe
|
commerce magento commerce_b2b
|
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged a…
|
NVD-CWE-noinfo
|
CVE-2024-45130
|
2024-10-12 07:08 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307302
|
4.8 |
MEDIUM
Network
|
adobe
|
commerce magento commerce_b2b
|
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malic…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45127
|
2024-10-12 07:06 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307303
|
4.3 |
MEDIUM
Network
|
adobe
|
commerce magento commerce_b2b
|
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged a…
|
CWE-863
Incorrect Authorization
|
CVE-2024-45125
|
2024-10-12 07:05 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307304
|
5.3 |
MEDIUM
Network
|
adobe
|
commerce magento commerce_b2b
|
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could …
|
NVD-CWE-noinfo
|
CVE-2024-45124
|
2024-10-12 07:05 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307305
|
5.9 |
MEDIUM
Network
|
syracom
|
secure_login
|
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidat…
|
NVD-CWE-noinfo
|
CVE-2024-48942
|
2024-10-12 06:36 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307306
|
5.4 |
MEDIUM
Network
|
syracom
|
secure_login
|
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucke…
|
NVD-CWE-noinfo
|
CVE-2024-48941
|
2024-10-12 06:36 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307307
|
- |
|
-
|
-
|
An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) and output arguments (out_vec). Th…
|
-
|
CVE-2024-45746
|
2024-10-12 06:36 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307308
|
- |
|
-
|
-
|
FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to…
|
-
|
CVE-2024-25825
|
2024-10-12 06:36 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307309
|
- |
|
-
|
-
|
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-38365. Reason: This record is a duplicate of CVE-2024-38365. Notes: All CVE users should reference CVE-2024-38365 instead of this rec…
|
-
|
CVE-2024-36051
|
2024-10-12 06:15 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307310
|
- |
|
-
|
-
|
Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker with local access to potentially enab…
|
-
|
CVE-2024-47975
|
2024-10-12 05:15 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|