Aggregator
【公告】JSRC八月英雄榜单揭晓
5 months ago
八月榜单终于来啦
【活动】14家SRC邀您加入双11安全保卫战
5 months ago
京东SRC活动时间:9.19-10.13
“探索无限量 安全新未来” 密码创新大会2024在京举办
5 months ago
聚焦量子科技及密码技术,探讨传统密码技术在量子计算时代的安全挑战及应对策略。
2024网安周 | 粤港澳携手共进 守护网安南大门
5 months ago
联动湾区,协同港澳,合力共建网络强国。
CVE-2024-41716 | IDEC WindLDR/WindO I-NV4 Project File cleartext storage
5 months ago
A vulnerability was found in IDEC WindLDR and WindO I-NV4 and classified as problematic. Affected by this issue is some unknown functionality of the component Project File Handler. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is handled as CVE-2024-41716. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-45442 | Huawei HarmonyOS/EMUI DownloadProviderMain Module access control
5 months ago
A vulnerability was found in Huawei HarmonyOS and EMUI. It has been rated as critical. Affected by this issue is some unknown functionality of the component DownloadProviderMain Module. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-45442. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2024-20439 | Cisco Smart License Utility 2.0.0/2.1.0/2.2.0 backdoor (cisco-sa-cslu-7gHMzWmw)
5 months ago
A vulnerability, which was classified as very critical, was found in Cisco Smart License Utility 2.0.0/2.1.0/2.2.0. Affected is an unknown function. The manipulation leads to backdoor.
This vulnerability is traded as CVE-2024-20439. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20503 | Cisco Duo Authentication for Epic up to 1.2.0.95 Registry Key information disclosure (cisco-sa-duo-epic-info-sdLv6h8y)
5 months ago
A vulnerability, which was classified as problematic, has been found in Cisco Duo Authentication for Epic up to 1.2.0.95. Affected by this issue is some unknown functionality of the component Registry Key Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-20503. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-1744 | Ariva Computer Accord ORS up to 7.3.2.0 information disclosure
5 months ago
A vulnerability, which was classified as problematic, was found in Ariva Computer Accord ORS up to 7.3.2.0. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-1744. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37068 | IBM Maximo Application Suite 8.10/8.11/9.0 Manage Component risky encryption (XFDB-292799)
5 months ago
A vulnerability was found in IBM Maximo Application Suite 8.10/8.11/9.0. It has been rated as problematic. This issue affects some unknown processing of the component Manage Component. The manipulation leads to risky cryptographic algorithm.
The identification of this vulnerability is CVE-2024-37068. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-34974 | QNAP QTS/QuTS hero/QuTScloud/QVR/QES os command injection (qsa-24-32)
5 months ago
A vulnerability, which was classified as critical, has been found in QNAP QTS, QuTS hero, QuTScloud, QVR and QES. Affected by this issue is some unknown functionality. The manipulation leads to os command injection.
This vulnerability is handled as CVE-2023-34974. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27125 | QNAP Helpdesk up to 3.3.0 cross site scripting (qsa-24-29)
5 months ago
A vulnerability was found in QNAP Helpdesk up to 3.3.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-27125. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27126 | QNAP Notes Station 3 prior 3.9.6 cross site scripting (qsa-24-21)
5 months ago
A vulnerability was found in QNAP Notes Station 3. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-27126. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27122 | QNAP Notes Station 3 up to 3.9.5 cross site scripting (qsa-24-21)
5 months ago
A vulnerability classified as problematic has been found in QNAP Notes Station 3 up to 3.9.5. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-27122. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-32762 | QNAP QuLog Center prior 1.7.0.827/1.8.0.872 cross site scripting (qsa-24-30)
5 months ago
A vulnerability classified as problematic was found in QNAP QuLog Center. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-32762. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38486 | Dell SmartFabric OS10 Software up to 10.5.5.10/10.5.6.x command injection (dsa-2024-376)
5 months ago
A vulnerability, which was classified as critical, has been found in Dell SmartFabric OS10 Software up to 10.5.5.10/10.5.6.x. Affected by this issue is some unknown functionality. The manipulation leads to command injection.
This vulnerability is handled as CVE-2024-38486. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-39585 | Dell SmartFabric OS10 Software up to 10.5.5.10/10.5.6.x hard-coded password (dsa-2024-377)
5 months ago
A vulnerability, which was classified as problematic, was found in Dell SmartFabric OS10 Software up to 10.5.5.10/10.5.6.x. This affects an unknown part. The manipulation leads to use of hard-coded password.
This vulnerability is uniquely identified as CVE-2024-39585. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-45429 | WP Engine Advanced Custom Fields/Advanced Custom Fields Pro up to 6.3.5 Setting label cross site scripting
5 months ago
A vulnerability was found in WP Engine Advanced Custom Fields and Advanced Custom Fields Pro up to 6.3.5. It has been rated as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation of the argument label leads to cross site scripting.
The identification of this vulnerability is CVE-2024-45429. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-45617 | libopensc uninitialized pointer
5 months ago
A vulnerability was found in libopensc. It has been classified as critical. Affected is an unknown function. The manipulation leads to uninitialized pointer.
This vulnerability is traded as CVE-2024-45617. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com