|
309121
|
7.5 |
HIGH
Network
|
cisco
|
ios_xr
|
A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP packet memory of an affected device…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-20304
|
2024-10-3 23:20 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309122
|
9.8 |
CRITICAL
Network
|
telerik
|
ui_for_wpf
|
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
|
CWE-77
Command Injection
|
CVE-2024-7575
|
2024-10-3 22:52 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309123
|
9.8 |
CRITICAL
Network
|
telerik
|
ui_for_wpf
|
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-7576
|
2024-10-3 22:51 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309124
|
7.5 |
HIGH
Network
|
cisco
|
ios ios_xe
|
A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to relo…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-20433
|
2024-10-3 22:34 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309125
|
9.8 |
CRITICAL
Network
|
tduckcloud
|
tduckpro
|
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The at…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2024-8692
|
2024-10-3 22:17 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309126
|
7.8 |
HIGH
Local
|
cisco
|
ios_xr
|
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device.
T…
|
CWE-78
OS Command
|
CVE-2024-20398
|
2024-10-3 10:47 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309127
|
7.2 |
HIGH
Network
|
cisco
|
ios_xr
|
Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacke…
|
CWE-78
OS Command
|
CVE-2024-20483
|
2024-10-3 10:44 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309128
|
5.5 |
MEDIUM
Local
|
cisco
|
ios_xr
|
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials.
This vulnerabilit…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-20489
|
2024-10-3 10:40 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309129
|
7.2 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.
|
CWE-78
OS Command
|
CVE-2024-8686
|
2024-10-3 10:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309130
|
7.8 |
HIGH
Local
|
telerik
|
ui_for_wpf
|
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-8316
|
2024-10-3 10:01 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|