Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2024-9380Alta7.2
Una vulnerabilità di OS command injection nella admin web console di Ivanti CSA prima della versione 5.0.2 consente a un attaccante remoto autenticato con privilegi di admin di ottenere remote code execution.
- CVE-2024-9379Media6.5
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
- CVE-2024-43047Alta7.8
Memory corruption while maintaining memory maps of HLOS memory.
- CVE-2024-45519Critica10.0
Il servizio postjournal in Zimbra Collaboration (ZCS) prima di 8.8.15 Patch 46, 9 prima di 9.0.0 Patch 41, 10 prima di 10.0.9 e 10.1 prima di 10.1.1 a volte consente agli utenti non autenticati di eseguire comandi.
- CVE-2024-8963Critica9.4
Path Traversal in Ivanti CSA prima di 4.6 Patch 519 consente a un attaccante remoto non autenticato di accedere a funzionalità ristrette.
- CVE-2024-8957Alta7.2
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.
- CVE-2024-8956Critica9.1
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.
- CVE-2024-38813Alta7.5
vCenter Server contiene una vulnerabilità di privilege escalation. Un attore malevolo con accesso di rete a vCenter Server può attivare questa vulnerabilità per elevare i privilegi a root inviando un pacchetto di rete appositamente predisposto.
- CVE-2024-38812Critica9.8
vCenter Server contiene una vulnerabilità heap-overflow nell'implementazione del protocollo DCERPC. Un attore malevolo con accesso di rete a vCenter Server può attivare questa vulnerabilità inviando un pacchetto di rete appositamente predisposto, con possibile esecuzione di codice da remoto.
- CVE-2024-6587Alta7.5
Esiste una vulnerabilità Server-Side Request Forgery (SSRF) in berriai/litellm versione 1.38.10. Questa vulnerabilità consente agli utenti di specificare il parametro `api_base` quando effettuano richieste a `POST /chat/completions`, facendo sì che l'applicazione invii la richiesta al dominio specificato da `api_base`. Questa richiesta include la chiave API di OpenAI. Un utente malintenzionato può impostare `api_base` sul proprio dominio e intercettare la chiave API di OpenAI, determinando un accesso non autorizzato e un potenziale uso improprio della chiave API.
- CVE-2024-8190Alta7.2
Una vulnerabilità di OS command injection in Ivanti Cloud Services Appliance versioni 4.6 Patch 518 e precedenti consente a un attaccante remoto autenticato di ottenere remote code execution. L'attaccante deve avere privilegi di livello admin per sfruttare questa vulnerabilità.
- CVE-2024-43461Alta8.8
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-38226Alta7.3
Microsoft Publisher Security Feature Bypass Vulnerability
- CVE-2024-38217Media5.4
Windows Mark of the Web Security Feature Bypass Vulnerability
- CVE-2024-38014Alta7.8
Windows Installer Elevation of Privilege Vulnerability
- CVE-2024-40711Critica9.8
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
- CVE-2024-20439Critica9.8
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API.
- CVE-2024-45195Alta7.5
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
- CVE-2024-6670Critica9.8
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
- CVE-2024-40766Critica9.8
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
This product uses the NVD API but is not endorsed or certified by the NVD.