|
308441
|
8.8 |
HIGH
Local
|
siemens
|
sinec_security_monitor
|
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-cl…
|
CWE-77
Command Injection
|
CVE-2024-47562
|
2024-10-12 05:04 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308442
|
9.9 |
CRITICAL
Network
|
siemens
|
sinec_security_monitor
|
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command.
This…
|
CWE-88
Argument Injection
|
CVE-2024-47553
|
2024-10-12 05:04 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308443
|
5.4 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
|
CWE-79
Cross-site Scripting
|
CVE-2024-47951
|
2024-10-12 04:57 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308444
|
5.4 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
|
CWE-79
Cross-site Scripting
|
CVE-2024-47950
|
2024-10-12 04:57 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308445
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
|
CWE-22
Path Traversal
|
CVE-2024-47949
|
2024-10-12 04:57 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308446
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
|
CWE-22
Path Traversal
|
CVE-2024-47948
|
2024-10-12 04:56 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308447
|
6.5 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-47161
|
2024-10-12 04:54 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308448
|
9.8 |
CRITICAL
Network
|
dlink
|
di-8400_firmware
|
A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the pat…
|
CWE-77
Command Injection
|
CVE-2024-44400
|
2024-10-12 02:15 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308449
|
7.8 |
HIGH
Local
|
libarchive
|
libarchive
|
execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-48957
|
2024-10-12 01:12 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308450
|
7.8 |
HIGH
Local
|
libarchive
|
libarchive
|
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-48958
|
2024-10-12 01:11 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|