Aggregator
CVE-2024-9264 | Grafana up to 11.2.1 SQL Expressions Experimental Feature PATH code injection
1 year 8 months ago
A vulnerability was found in Grafana up to 11.2.1. It has been classified as critical. This affects an unknown part of the component SQL Expressions Experimental Feature. The manipulation of the argument PATH leads to code injection.
This vulnerability is uniquely identified as CVE-2024-9264. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-30875 | jQuery-UI 1.13.1 window.addEventListener cross site scripting
1 year 8 months ago
A vulnerability was found in jQuery-UI 1.13.1 and classified as problematic. Affected by this issue is the function window.addEventListener. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-30875. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-26785 | MariaDB 10.5 code injection
1 year 8 months ago
A vulnerability has been found in MariaDB 10.5 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to code injection.
This vulnerability is known as CVE-2023-26785. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10118 | SECOM WRTR-304GN-304TW-UPSC os command injection
1 year 8 months ago
A vulnerability, which was classified as very critical, was found in SECOM WRTR-304GN-304TW-UPSC. Affected is an unknown function. The manipulation leads to os command injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2024-10118. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
RansomHub
1 year 8 months ago
cohenido
CVE-2024-7316 | Mitsubishi Electric CNC M800VW Service Port 683 improper validation of specified quantity in input
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in Mitsubishi Electric CNC M800VW, CNC M800VS, CNC M80V, CNC M80VW, CNC M800W, CNC M800S, CNC M80, CNC M80W, CNC E80, CNC C80, CNC M720VW, CNC M730VW, CNC M750VW, CNC M720VS, CNC M730VS, CNC M750VS, CNC M70V, CNC E70, CNC Software Tools NC Trainer2 and CNC Software Tools NC Trainer2 Plus. This issue affects some unknown processing of the component Service Port 683. The manipulation leads to improper validation of specified quantity in input.
The identification of this vulnerability is CVE-2024-7316. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-48924 | MessagePack-CSharp up to 2.5.186/3.0.213 GetHashCollisionResistantEqualityComparer weak hash (GHSA-7q36-4xx7-xcxf)
1 year 8 months ago
A vulnerability classified as critical was found in MessagePack-CSharp up to 2.5.186/3.0.213. This vulnerability affects the function GetHashCollisionResistantEqualityComparer. The manipulation leads to use of weak hash.
This vulnerability was named CVE-2024-48924. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
RansomHub
1 year 8 months ago
cohenido
Cicada3301
1 year 8 months ago
cohenido
RansomHub
1 year 8 months ago
cohenido
CVE-2023-39593 | MariaDB 10.5 sys_exec code injection
1 year 8 months ago
A vulnerability classified as critical has been found in MariaDB 10.5. This affects the function sys_exec. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2023-39593. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
RansomHub
1 year 8 months ago
cohenido
JVN: LCDS製LAquis SCADAにおけるクロスサイトスクリプティングの脆弱性
1 year 8 months ago
LCDSが提供するLAquis SCADAには、クロスサイトスクリプティングの脆弱性が存在します。
Despite massive security spending, 44% of CISOs fail to detect breaches
1 year 8 months ago
Despite global information security spending projected to reach $215 billion in 2024, 44% of CISOs surveyed reported they were unable to detect a data breach in the last 12 months using existing security tools, according to Gigamon. Blind spots undermine breach detection CISOs identified blind spots as a key issue, with 70% of CISOs stating their existing security tools are not as effective as they could be when it comes to detecting breaches due to … More →
The post Despite massive security spending, 44% of CISOs fail to detect breaches appeared first on Help Net Security.
Help Net Security
JVN: HMS Networks製Ewon Flexy 202における認証情報の不十分な保護の脆弱性
1 year 8 months ago
HMS Networksが提供するEwon Flexy 202には、認証情報の不十分な保護の脆弱性が存在します。
CVE-2024-43580 | Microsoft Edge up to 129.0.2792.52 insufficient warning (Nessus ID 209257)
1 year 8 months ago
A vulnerability was found in Microsoft Edge. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to insufficient ui warning of dangerous operations.
This vulnerability is handled as CVE-2024-43580. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43596 | Microsoft Edge up to 129.0.2792.52 type confusion (Nessus ID 209257)
1 year 8 months ago
A vulnerability was found in Microsoft Edge. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to type confusion.
This vulnerability is known as CVE-2024-43596. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43595 | Microsoft Edge up to 129.0.2792.52 buffer over-read (Nessus ID 209257)
1 year 8 months ago
A vulnerability was found in Microsoft Edge. It has been classified as problematic. Affected is an unknown function. The manipulation leads to buffer over-read.
This vulnerability is traded as CVE-2024-43595. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43587 | Microsoft Edge up to 129.0.2792.52 heap-based overflow (Nessus ID 209257)
1 year 8 months ago
A vulnerability was found in Microsoft Edge and classified as problematic. This issue affects some unknown processing. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2024-43587. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com