Base de données CVE
- CVE-2024-38107Élevée7.8
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
- CVE-2024-38106Élevée7.0
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-41710Élevée7.2
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
- CVE-2024-27443Moyenne6.1
Un problème a été découvert dans Zimbra Collaboration (ZCS) 9.0 et 10.0. Une vulnérabilité Cross-Site Scripting (XSS) existe dans la fonctionnalité CalendarInvite de l'interface utilisateur classique Zimbra webmail, en raison d'une validation incorrecte des entrées dans la gestion de l'en-tête de calendrier. Un attaquant peut l'exploiter via un message électronique contenant un en-tête de calendrier forgé avec un payload XSS intégré. Lorsqu'une victime consulte ce message dans l'interface classique Zimbra webmail, le payload est exécuté dans le contexte de la session de la victime, pouvant conduire à l'exécution de code JavaScript arbitraire.
- CVE-2024-7694Élevée7.2
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
- CVE-2024-7399Élevée8.8
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
- CVE-2024-42009Critique9.3
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
- CVE-2024-38856Critique9.8
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
- CVE-2023-45249Critique9.8
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
- CVE-2024-21182Élevée7.5
Vulnérabilité dans le produit Oracle WebLogic Server d'Oracle Fusion Middleware (composant : Core). Les versions prises en charge affectées sont 12.2.1.4.0 et 14.1.1.0.0. Une vulnérabilité facilement exploitable permet à un attaquant non authentifié disposant d'un accès réseau via T3, IIOP de compromettre Oracle WebLogic Server. Les attaques réussies de cette vulnérabilité peuvent entraîner un accès non autorisé à des données critiques ou un accès complet à toutes les données accessibles par Oracle WebLogic Server. Score de base CVSS 3.1 7.5 (impacts sur la confidentialité). Vecteur CVSS : (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- CVE-2024-5910Critique9.8
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
- CVE-2024-5217Critique9.8
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
- CVE-2024-4879Critique9.8
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
- CVE-2024-38112Élevée7.5
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-38094Élevée7.2
Microsoft SharePoint Remote Code Execution Vulnerability
- CVE-2024-38080Élevée7.8
Windows Hyper-V Elevation of Privilege Vulnerability
- CVE-2024-39891Moyenne5.3
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)
- CVE-2024-38475Critique9.1
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
- CVE-2024-20399Moyenne6.0
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode
- CVE-2024-36401Critique9.8
GeoServer est un serveur open source qui permet aux utilisateurs de partager et de modifier des données géospatiales. Avant les versions 2.22.6, 2.23.6, 2.24.4 et 2.25.2, de multiples paramètres de requête OGC permettent l'exécution de code à distance (RCE) par des utilisateurs non authentifiés via une entrée spécialement conçue contre une installation GeoServer par défaut en raison de l'évaluation non sécurisée des noms de propriétés en tant qu'expressions XPath. L'API de la bibliothèque GeoTools appelée par GeoServer évalue les noms de propriétés/attributs pour les types d'entités d'une manière qui les transmet de façon non sécurisée à la bibliothèque commons-jxpath qui peut exécuter du code arbitraire lors de l'évaluation des expressions XPath. Cette évaluation XPath est destinée à être utilisée uniquement par les types d'entités complexes (c.-à-d. les magasins de données Application Schema) mais est incorrectement appliquée également aux types d'entités simples, ce qui fait que cette vulnérabilité s'applique à **TOUTES** les instances GeoServer. Aucun PoC public n'est fourni mais il a été confirmé que cette vulnérabilité est exploitable via les requêtes WFS GetFeature, WFS GetPropertyValue, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic et WPS Execute. Cette vulnérabilité peut conduire à l'exécution de code arbitraire. Les versions 2.22.6, 2.23.6, 2.24.4 et 2.25.2 contiennent un correctif pour ce problème. Une solution de contournement existe en supprimant le fichier `gt-complex-x.y.jar` du GeoServer où `x.y` est la version GeoTools (p. ex. `gt-complex-31.1.jar` si vous exécutez GeoServer 2.25.1). Cela supprimera le code vulnérable de GeoServer mais peut interrompre certaines fonctionnalités de GeoServer ou empêcher le déploiement de GeoServer si le module gt-complex est nécessaire.
This product uses the NVD API but is not endorsed or certified by the NVD.