NCC Group discovered vulnerabilities in Sonos smart speakers, including a flaw that could have allowed to eavesdrop on users. Researchers from NCC Group have discovered multiple vulnerabilities in Sonos smart speakers, including a flaw, tracked as CVE-2023-50809, that could have allowed eavesdropping on users. The researchers have disclosed the vulnerabilities during the BLACK HAT USA […]
A vulnerability, which was classified as problematic, was found in Christmasify Plugin up to 1.5.5 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-7574. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in Opal Membership Plugin up to 1.2.4 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-7649. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic was found in Opal Membership Plugin up to 1.2.4 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-7648. The attack can be launched remotely. There is no exploit available.
A vulnerability classified as critical has been found in Havoc 0.7. Affected is an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2024-41570. Access to the local network is required for this attack. There is no exploit available.
A vulnerability was found in productinfoquick 1.0. It has been rated as problematic. This issue affects some unknown processing of the component Ueditor. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-41577. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability was found in vercot Serva 4.6.0. It has been declared as problematic. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-37826. The attack needs to be done within the local network. There is no exploit available.
A vulnerability was found in openhab-webui up to 4.2.0. It has been classified as critical. This affects an unknown part. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-42467. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in QNAP QTS and QuTS hero 5.1.3.2578 Build 20231110/5.1.4.2596 Build 20231128 and classified as problematic. Affected by this issue is some unknown functionality of the component Network / Virtual Switch. The manipulation leads to reliance on ip address for authentication.
This vulnerability is handled as CVE-2024-32765. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in OpenFGA 1.5.7/1.5.8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Check API. The manipulation leads to incorrect authorization.
This vulnerability is known as CVE-2024-42473. The attack can be launched remotely. There is no exploit available.
It is recommended to apply the suggested workaround.
A vulnerability, which was classified as critical, was found in openhab-webui up to 4.2.0. Affected is an unknown function. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2024-42468. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in izatop bunt 0.29.19. This vulnerability affects unknown code of the file /esm/qs.js of the component Property Handler. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution').
This vulnerability was named CVE-2024-38989. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. This affects the function delete_category of the component Category Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2024-41332. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in litestar up to 2.10.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file docs-preview.yml of the component Environment Variable Handler. The manipulation of the argument DOCS_PREVIEW_DEPLOY_TOKEN leads to os command injection.
This vulnerability is handled as CVE-2024-42370. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in openhab-webui up to 4.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-42470. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Sonos S1 and S2. It has been classified as critical. Affected is an unknown function in the library mt_7615.ko of the component Wireless Driver. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2023-50809. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in openhab-webui up to 4.2.0 and classified as critical. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-42469. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in aio-libs aiohttp up to 3.10.1 and classified as critical. This vulnerability affects unknown code. The manipulation leads to symlink following.
This vulnerability was named CVE-2024-42367. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.