|
312561
|
7.5 |
HIGH
Network
|
vonets
|
var1200-h_firmware var1200-l_firmware var600-h_firmware vap11ac_firmware vap11g-500s_firmware vbg1200_firmware vap11s-5g_firmware vap11s_firmware var11n-300_firmware vap11g…
|
A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9
and prior, enables an unauthenticated remote attacker to re…
|
CWE-22
Path Traversal
|
CVE-2024-41936
|
2024-08-21 01:26 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312562
|
7.8 |
HIGH
Local
|
paloaltonetworks
|
globalprotect
|
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-5915
|
2024-08-21 01:23 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312563
|
9.8 |
CRITICAL
Network
|
paloaltonetworks
|
cortex_xsoar_commonscripts
|
A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.
|
CWE-77
Command Injection
|
CVE-2024-5914
|
2024-08-21 01:22 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312564
|
9.8 |
CRITICAL
Network
|
opensecurity
|
mobile_security_framework
|
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static L…
|
CWE-22
Path Traversal
|
CVE-2024-43399
|
2024-08-21 01:21 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312565
|
9.8 |
CRITICAL
Network
|
dell
|
dns-120_firmware dnr-202l_firmware dns-315l_firmware dns-320_firmware dns-320l_firmware dns-320lw_firmware dns-321_firmware dnr-322l_firmware dns-323_firmware dns-325_firmw…
|
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, …
|
CWE-77
Command Injection
|
CVE-2024-7922
|
2024-08-21 01:20 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312566
|
7.5 |
HIGH
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the clea…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-38891
|
2024-08-21 01:19 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312567
|
8.8 |
HIGH
Network
|
linksys
|
e1500_firmware
|
A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root pri…
|
CWE-78
OS Command
|
CVE-2024-42633
|
2024-08-21 01:18 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312568
|
7.5 |
HIGH
Network
|
nissan-global
|
blind_spot_protection_sensor_ecu_firmware
|
Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2024-6348
|
2024-08-21 01:17 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312569
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the databas…
|
CWE-78
OS Command
|
CVE-2024-38887
|
2024-08-21 01:17 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312570
|
7.8 |
HIGH
Local
|
google
|
android
|
In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
|
CWE-416
Use After Free
|
CVE-2024-32927
|
2024-08-21 01:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|