Common Vulnerabilities and Exposures (CVE)

CVE-2023-41675

Sep 18, 2024 20:04:30 UTC

A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to cras...

CVE-2023-44959

Sep 18, 2024 20:02:43 UTC

An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page.

CVE-2023-45312

Sep 18, 2024 19:49:40 UTC

In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability.

CVE-2022-22298

Sep 18, 2024 19:48:48 UTC

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 throug...

CVE-2024-21871

Sep 18, 2024 19:46:23 UTC

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2024-45592

Sep 18, 2024 19:38:07 UTC

auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because `%sou...

CVE-2023-25604

Sep 18, 2024 19:37:45 UTC

An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext passwords in the RADIUS logs.

CVE-2023-43696

Sep 18, 2024 19:37:28 UTC

Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.

CVE-2024-7143

Sep 18, 2024 19:33:00 UTC

A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method f...

CVE-2024-7383

Sep 18, 2024 19:32:04 UTC

A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.

CVE-2024-39339

Sep 18, 2024 19:31:26 UTC

A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, ...

CVE-2024-43025

Sep 18, 2024 19:22:43 UTC

An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent e-mail.

CVE-2024-43024

Sep 18, 2024 19:18:47 UTC

Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-45613

Sep 18, 2024 19:18:15 UTC

In JetBrains Ktor before 2.3.5 server certificates were not verified

CVE-2024-44589

Sep 18, 2024 19:13:07 UTC

Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.