CWE:
 

Topic
Date
Author
High
Zyxel MAX3XX Series Wimax CPEs Hardcoded Root Password
24.03.2016
Gianni Carabelli


CVEMAP Search Results

CVE
Details
Description
2024-10-09
Waiting for details
CVE-2024-7041

Updating...
 

 
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper authorization.

 
2024-10-08
Waiting for details
CVE-2024-43583

Updating...
 

 
Winlogon Elevation of Privilege Vulnerability

 
2024-09-26
Waiting for details
CVE-2024-31899

Updating...
 

 
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.

 
2024-09-25
Waiting for details
CVE-2024-43423

Updating...
 

 
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

 
2024-09-23
Waiting for details
CVE-2024-8903

Updating...
 

 
Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

 
2024-09-18
Waiting for details
CVE-2024-5960

Updating...
 

 
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.

 
2024-09-17
Waiting for details
CVE-2024-7387

Updating...
 

 
A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the �??Docker�?� strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.

 
Waiting for details
CVE-2024-8767

Updating...
 

 
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.

 
2024-09-10
Waiting for details
CVE-2024-45283

Updating...
 

 
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.

 
Waiting for details
CVE-2024-35783

Updating...
 

 
A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions), SIMATIC Information Server 2022 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC Process Historian 2020 (All versions), SIMATIC Process Historian 2022 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.

 

 


Copyright 2024, cxsecurity.com

 

Back to Top