|
305761
|
9.8 |
CRITICAL
Network
|
projectworlds
|
life_insurance_management_system
|
A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file /editPayment.php. The manipulation of th…
|
CWE-89
SQL Injection
|
CVE-2024-10734
|
2024-11-6 04:43 |
2024-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305762
|
8.6 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_software firepower_threat_defense_software
|
A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could…
|
NVD-CWE-noinfo
|
CVE-2024-20426
|
2024-11-6 04:43 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305763
|
9.8 |
CRITICAL
Network
|
esafenet
|
cdg
|
A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. This issue affects the function actionPassDecryptApplication1 of the file /com/esafenet/servlet/client/DecryptApplicationSe…
|
CWE-89
SQL Injection
|
CVE-2024-10377
|
2024-11-6 04:41 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305764
|
9.8 |
CRITICAL
Network
|
esafenet
|
cdg
|
A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects the function actionPassOrNotAutoSign of the file /com/esafenet/servlet/service/processsign/Au…
|
CWE-89
SQL Injection
|
CVE-2024-10376
|
2024-11-6 04:41 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305765
|
6.1 |
MEDIUM
Network
|
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers.
Accessing a crafted URL which points to an…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2024-47549
|
2024-11-6 04:40 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305766
|
7.5 |
HIGH
Network
|
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability.
Crafted HTTP requests may cause affected products crashed.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-43424
|
2024-11-6 04:39 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305767
|
7.5 |
HIGH
Network
|
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages.
Crafted HTTP requests may…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-42420
|
2024-11-6 04:39 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305768
|
7.5 |
HIGH
Network
|
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability.
Crafted HTTP …
|
CWE-125
Out-of-bounds Read
|
CVE-2024-45829
|
2024-11-6 04:38 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305769
|
5.3 |
MEDIUM
Network
|
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability.
Unintended internal files may be retrieved when processing crafted HTTP reque…
|
CWE-22
Path Traversal
|
CVE-2024-45842
|
2024-11-6 04:37 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305770
|
- |
|
-
|
-
|
The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the ellipt…
|
-
|
CVE-2024-48948
|
2024-11-6 04:36 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|