Base de données CVE
- CVE-2024-41713Critique9.1
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
- CVE-2024-9537Critique9.8
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.
- CVE-2024-9465Critique9.1
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
- CVE-2024-9463Élevée7.5
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
- CVE-2024-9680Critique9.8
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
- CVE-2024-43573Moyenne6.5
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-43572Élevée7.8
Microsoft Management Console Remote Code Execution Vulnerability
- CVE-2024-43468Critique9.8
Microsoft Configuration Manager Remote Code Execution Vulnerability
- CVE-2024-9380Élevée7.2
Une vulnérabilité d'injection de commandes OS dans la console web d'administration d'Ivanti CSA avant la version 5.0.2 permet à un attaquant distant authentifié disposant de privilèges administrateur d'obtenir une exécution de code à distance.
- CVE-2024-9379Moyenne6.5
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
- CVE-2024-43047Élevée7.8
Memory corruption while maintaining memory maps of HLOS memory.
- CVE-2024-45519Critique10.0
Le service postjournal dans Zimbra Collaboration (ZCS) avant 8.8.15 Patch 46, 9 avant 9.0.0 Patch 41, 10 avant 10.0.9, et 10.1 avant 10.1.1 permet parfois aux utilisateurs non authentifiés d'exécuter des commandes.
- CVE-2024-8963Critique9.4
Path Traversal dans Ivanti CSA avant 4.6 Patch 519 permet à un attaquant distant non authentifié d'accéder à des fonctionnalités restreintes.
- CVE-2024-8957Élevée7.2
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.
- CVE-2024-8956Critique9.1
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.
- CVE-2024-38813Élevée7.5
Le vCenter Server contient une vulnérabilité d'élévation de privilèges. Un acteur malveillant disposant d'un accès réseau à vCenter Server peut exploiter cette vulnérabilité pour élever les privilèges au niveau root en envoyant un paquet réseau spécialement conçu.
- CVE-2024-38812Critique9.8
Le vCenter Server contient une vulnérabilité heap-overflow dans l'implémentation du protocole DCERPC. Un acteur malveillant disposant d'un accès réseau à vCenter Server peut déclencher cette vulnérabilité en envoyant un paquet réseau spécialement conçu, pouvant potentiellement conduire à une exécution de code à distance.
- CVE-2024-6587Élevée7.5
Une vulnérabilité de type Server-Side Request Forgery (SSRF) existe dans berriai/litellm version 1.38.10. Cette vulnérabilité permet aux utilisateurs de spécifier le paramètre `api_base` lors de requêtes vers `POST /chat/completions`, amenant l'application à envoyer la requête au domaine spécifié par `api_base`. Cette requête inclut la clé API OpenAI. Un utilisateur malveillant peut définir `api_base` sur son propre domaine et intercepter la clé API OpenAI, entraînant un accès non autorisé et une utilisation abusive potentielle de la clé API.
- CVE-2024-8190Élevée7.2
Une vulnérabilité d'injection de commandes OS dans Ivanti Cloud Services Appliance versions 4.6 Patch 518 et antérieures permet à un attaquant distant authentifié d'obtenir une exécution de code à distance. L'attaquant doit disposer de privilèges de niveau administrateur pour exploiter cette vulnérabilité.
- CVE-2024-43461Élevée8.8
Windows MSHTML Platform Spoofing Vulnerability
This product uses the NVD API but is not endorsed or certified by the NVD.