Category: CVE

CVE-2024-50810 | hopetree izone c011b48 Article Comment appscommentviews.py AddCommintView cross site scripting (Issue 289)

A vulnerability, which was classified as problematic, has been found in hopetree izone c011b48. Affected by this issue is the function AddCommintView of the file appscommentviews.py of the component Article Comment Handler. The manipulation leads to cross site scripting. This vulnerability is handled as CVE-2024-50810. The attack may be launched remotely. There is no exploit...

Read More

CVE-2024-50811 | hopetree izone c011b48 bd_push.py push_urls/get_urls server-side request forgery (Issue 290)

A vulnerability classified as critical was found in hopetree izone c011b48. Affected by this vulnerability is the function push_urls/get_urls of the file appstoolapisbd_push.py. The manipulation leads to server-side request forgery. This vulnerability is known as CVE-2024-50811. The attack needs to be done within the local network. There is no exploit...

Read More

CVE-2024-9841 | OpenText ArcSight Management Center/ArcSight Platform cross site scripting (KM000035977)

A vulnerability was found in OpenText ArcSight Management Center and ArcSight Platform. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-9841. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-40239 | Life Personal Diary App 17.5.0 on Android Fingerprint Authentication access control

A vulnerability was found in Life Personal Diary App 17.5.0 on Android. It has been declared as critical. This vulnerability affects unknown code of the component Fingerprint Authentication. The manipulation leads to improper access controls. This vulnerability was named CVE-2024-40239. It is possible to launch the attack on the physical device. There is no exploit...

Read More

CVE-2024-40240 | HomeServe Home Repair App 3.3.4 on Android Fingerprint Authentication access control

A vulnerability was found in HomeServe Home Repair App 3.3.4 on Android. It has been classified as critical. This affects an unknown part of the component Fingerprint Authentication. The manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-2024-40240. It is possible to launch the attack on the physical device. There is no exploit...

Read More

CVE-2024-51997 | confidential-containers trustee up to 0.8.1 ART Token Privilege Escalation

A vulnerability has been found in confidential-containers trustee up to 0.8.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component ART Token Handler. The manipulation leads to Privilege Escalation. This vulnerability is known as CVE-2024-51997. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-45763 | Dell Enterprise SONiC OS up to 4.1.5/4.2.1 os command injection (dsa-2024-449)

A vulnerability, which was classified as critical, was found in Dell Enterprise SONiC OS up to 4.1.5/4.2.1. Affected is an unknown function. The manipulation leads to os command injection. This vulnerability is traded as CVE-2024-45763. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-45765 | Dell Enterprise SONiC OS up to 4.1.5/4.2.1 os command injection (dsa-2024-449)

A vulnerability, which was classified as critical, has been found in Dell Enterprise SONiC OS up to 4.1.5/4.2.1. This issue affects some unknown processing. The manipulation leads to os command injection. The identification of this vulnerability is CVE-2024-45765. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-45764 | Dell Enterprise SONiC OS up to 4.1.5/4.2.1 missing critical step in authentication (dsa-2024-449)

A vulnerability classified as critical was found in Dell Enterprise SONiC OS up to 4.1.5/4.2.1. This vulnerability affects unknown code. The manipulation leads to missing critical step in authentication. This vulnerability was named CVE-2024-45764. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More
Loading