CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2024-51378Kritisch10.0
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.
- CVE-2024-50623Kritisch9.8
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
- CVE-2024-20481Mittel5.8
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected. Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials.
- CVE-2024-47575Kritisch9.8
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
- CVE-2024-41713Kritisch9.1
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
- CVE-2024-9537Kritisch9.8
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.
- CVE-2024-9465Kritisch9.1
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
- CVE-2024-9463Hoch7.5
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
- CVE-2024-9680Kritisch9.8
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
- CVE-2024-43573Mittel6.5
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-43572Hoch7.8
Microsoft Management Console Remote Code Execution Vulnerability
- CVE-2024-43468Kritisch9.8
Microsoft Configuration Manager Remote Code Execution Vulnerability
- CVE-2024-9380Hoch7.2
Eine OS-Command-Injection-Schwachstelle in der Admin-Webkonsole von Ivanti CSA vor Version 5.0.2 ermöglicht einem remote authentifizierten Angreifer mit Admin-Privilegien Remote Code Execution zu erlangen.
- CVE-2024-9379Mittel6.5
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
- CVE-2024-43047Hoch7.8
Memory corruption while maintaining memory maps of HLOS memory.
- CVE-2024-45519Kritisch10.0
Der postjournal-Dienst in Zimbra Collaboration (ZCS) vor 8.8.15 Patch 46, 9 vor 9.0.0 Patch 41, 10 vor 10.0.9 und 10.1 vor 10.1.1 erlaubt nicht authentifizierten Benutzern manchmal die Ausführung von Befehlen.
- CVE-2024-8963Kritisch9.4
Path Traversal im Ivanti CSA vor 4.6 Patch 519 ermöglicht einem nicht authentifizierten Remote-Angreifer den Zugriff auf eingeschränkte Funktionalität.
- CVE-2024-8957Hoch7.2
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.
- CVE-2024-8956Kritisch9.1
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.
- CVE-2024-45811Mittel4.8
Vite ist ein Frontend-Build-Tooling-Framework für JavaScript. In betroffenen Versionen können die Inhalte beliebiger Dateien an den Browser zurückgegeben werden. `@fs` verweigert den Zugriff auf Dateien außerhalb der Vite-Serving-Allow-Liste. Das Hinzufügen von `?import&raw` zur URL umgeht diese Einschränkung und gibt den Dateiinhalt zurück, sofern die Datei existiert. Dieses Problem wurde in den Versionen 5.4.6, 5.3.6, 5.2.14, 4.5.5 und 3.2.11 behoben. Benutzern wird empfohlen, ein Upgrade durchzuführen. Für diese Sicherheitslücke sind keine bekannten Umgehungslösungen vorhanden.
This product uses the NVD API but is not endorsed or certified by the NVD.