Aggregator
CVE-2023-39593 | MariaDB 10.5 sys_exec code injection
2 months 3 weeks ago
A vulnerability classified as critical has been found in MariaDB 10.5. This affects the function sys_exec. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2023-39593. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
RansomHub
2 months 3 weeks ago
cohenido
JVN: LCDS製LAquis SCADAにおけるクロスサイトスクリプティングの脆弱性
2 months 3 weeks ago
LCDSが提供するLAquis SCADAには、クロスサイトスクリプティングの脆弱性が存在します。
Despite massive security spending, 44% of CISOs fail to detect breaches
2 months 3 weeks ago
Despite global information security spending projected to reach $215 billion in 2024, 44% of CISOs surveyed reported they were unable to detect a data breach in the last 12 months using existing security tools, according to Gigamon. Blind spots undermine breach detection CISOs identified blind spots as a key issue, with 70% of CISOs stating their existing security tools are not as effective as they could be when it comes to detecting breaches due to … More →
The post Despite massive security spending, 44% of CISOs fail to detect breaches appeared first on Help Net Security.
Help Net Security
JVN: HMS Networks製Ewon Flexy 202における認証情報の不十分な保護の脆弱性
2 months 3 weeks ago
HMS Networksが提供するEwon Flexy 202には、認証情報の不十分な保護の脆弱性が存在します。
CVE-2024-43580 | Microsoft Edge up to 129.0.2792.52 insufficient warning (Nessus ID 209257)
2 months 3 weeks ago
A vulnerability was found in Microsoft Edge. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to insufficient ui warning of dangerous operations.
This vulnerability is handled as CVE-2024-43580. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43596 | Microsoft Edge up to 129.0.2792.52 type confusion (Nessus ID 209257)
2 months 3 weeks ago
A vulnerability was found in Microsoft Edge. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to type confusion.
This vulnerability is known as CVE-2024-43596. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43595 | Microsoft Edge up to 129.0.2792.52 buffer over-read (Nessus ID 209257)
2 months 3 weeks ago
A vulnerability was found in Microsoft Edge. It has been classified as problematic. Affected is an unknown function. The manipulation leads to buffer over-read.
This vulnerability is traded as CVE-2024-43595. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43587 | Microsoft Edge up to 129.0.2792.52 heap-based overflow (Nessus ID 209257)
2 months 3 weeks ago
A vulnerability was found in Microsoft Edge and classified as problematic. This issue affects some unknown processing. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2024-43587. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43579 | Microsoft Edge up to 129.0.2792.52 heap-based overflow (Nessus ID 209257)
2 months 3 weeks ago
A vulnerability has been found in Microsoft Edge and classified as critical. This vulnerability affects unknown code. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2024-43579. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43578 | Microsoft Edge up to 129.0.2792.52 heap-based overflow (Nessus ID 209257)
2 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Microsoft Edge. This affects an unknown part. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-43578. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43566 | Microsoft Edge up to 129.0.2792.52 integer overflow (Nessus ID 209257)
2 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Microsoft Edge. Affected by this issue is some unknown functionality. The manipulation leads to integer overflow.
This vulnerability is handled as CVE-2024-43566. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49023 | Microsoft Edge up to 129.0.2792.52 use after free
2 months 3 weeks ago
A vulnerability classified as problematic was found in Microsoft Edge. Affected by this vulnerability is an unknown functionality. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-49023. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3322 | parisneo lollms-webui up to 9.4 processor.py' path traversal
2 months 3 weeks ago
A vulnerability was found in parisneo lollms-webui up to 9.4. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file lollms-webui/zoos/personalities_zoo/cyber_security/codeguard/scripts/processor.py'. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-3322. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-4851 | stangirard quivr HTTP Request crawl_routes.py crawl_endpoint server-side request forgery
2 months 3 weeks ago
A vulnerability, which was classified as critical, was found in stangirard quivr. This affects the function crawl_endpoint of the file backend/routes/crawl_routes.py of the component HTTP Request Handler. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-4851. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-5124 | gaizhenbiao chuanhuchatgpt information disclosure
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in gaizhenbiao chuanhuchatgpt. Affected is an unknown function. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-5124. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-5248 | lunary-ai lunary up to latest /v1/users/me/org access control
2 months 3 weeks ago
A vulnerability was found in lunary-ai lunary up to latest. It has been rated as critical. This issue affects some unknown processing of the file /v1/users/me/org. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-5248. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-3095 | langchain-ai langchain up to 0.1.5 Web Research Retriever server-side request forgery
2 months 3 weeks ago
A vulnerability was found in langchain-ai langchain up to 0.1.5 and classified as problematic. This issue affects some unknown processing of the component Web Research Retriever. The manipulation leads to server-side request forgery.
The identification of this vulnerability is CVE-2024-3095. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2024-4320 | parisneo lollms-webui /install_extension ExtensionBuilder name path traversal
2 months 3 weeks ago
A vulnerability has been found in parisneo lollms-webui and classified as very critical. Affected by this vulnerability is the function ExtensionBuilder of the file /install_extension. The manipulation of the argument name leads to path traversal: '\..\filename'.
This vulnerability is known as CVE-2024-4320. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com