|
307981
|
9.8 |
CRITICAL
Network
|
endress
|
echo_curve_viewer fieldcare_sfe500_package field_xpert_smt79_firmware field_xpert_smt77_firmware field_xpert_smt70_firmware field_xpert_smt50_firmware
|
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
|
CWE-94
Code Injection
|
CVE-2024-6596
|
2024-10-1 21:26 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307982
|
9.8 |
CRITICAL
Network
|
openfga
|
openfga
|
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a us…
|
CWE-863
Incorrect Authorization
|
CVE-2024-42473
|
2024-10-1 21:21 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307983
|
9.8 |
CRITICAL
Network
|
mayurik
|
advocate_office_management_system
|
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /control/forgot_pass.php. The manipu…
|
CWE-89
SQL Injection
|
CVE-2024-9296
|
2024-10-1 20:36 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307984
|
9.8 |
CRITICAL
Network
|
mayurik
|
advocate_office_management_system
|
A vulnerability was found in SourceCodester Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /control/login.php. The manipulati…
|
CWE-89
SQL Injection
|
CVE-2024-9295
|
2024-10-1 20:36 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307985
|
9.8 |
CRITICAL
Network
|
mayurik
|
advocate_office_management_system
|
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /control/edit_client.php. The …
|
CWE-89
SQL Injection
|
CVE-2024-9328
|
2024-10-1 20:34 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307986
|
5.4 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to r…
|
NVD-CWE-noinfo
|
CVE-2024-42406
|
2024-10-1 20:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307987
|
4.4 |
MEDIUM
Local
|
codesys
|
oscat_basic_library
|
Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a crash of the affected service.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-6876
|
2024-10-1 16:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307988
|
7.3 |
HIGH
Local
|
beckhoff
|
twincat\/bsd mdp_package
|
The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local
attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in
the context of user “roo…
|
NVD-CWE-Other
|
CVE-2024-41176
|
2024-10-1 16:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307989
|
8.1 |
HIGH
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua…
|
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP …
|
NVD-CWE-noinfo
|
CVE-2024-43393
|
2024-10-1 16:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307990
|
8.1 |
HIGH
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mguard_rs2000_4g_vzw_vpn_firmware tc_mgua…
|
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP …
|
NVD-CWE-noinfo
|
CVE-2024-43392
|
2024-10-1 16:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|