Aggregator
CVE-2024-40735 | Netbox 4.0.3 edit Name cross site scripting
1 year 1 month ago
A vulnerability was found in Netbox 4.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /dcim/power-outlets/{id}/edit/. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is handled as CVE-2024-40735. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-40736 | Netbox 4.0.3 /dcim/power-outlets/add Name cross site scripting
1 year 1 month ago
A vulnerability classified as problematic has been found in Netbox 4.0.3. This affects an unknown part of the file /dcim/power-outlets/add. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-40736. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-40737 | Netbox 4.0.3 /dcim/console-ports/add Name cross site scripting
1 year 1 month ago
A vulnerability classified as problematic was found in Netbox 4.0.3. This vulnerability affects unknown code of the file /dcim/console-ports/add. The manipulation of the argument Name leads to cross site scripting.
This vulnerability was named CVE-2024-40737. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-40740 | Netbox 4.0.3 edit Name cross site scripting
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in Netbox 4.0.3. This issue affects some unknown processing of the file /dcim/power-feeds/{id}/edit/. The manipulation of the argument Name leads to cross site scripting.
The identification of this vulnerability is CVE-2024-40740. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-40738 | Netbox 4.0.3 edit Name cross site scripting
1 year 1 month ago
A vulnerability, which was classified as problematic, was found in Netbox 4.0.3. Affected is an unknown function of the file /dcim/console-ports/{id}/edit/. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is traded as CVE-2024-40738. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-40739 | Netbox 4.0.3 /dcim/power-feeds/add Name cross site scripting
1 year 1 month ago
A vulnerability has been found in Netbox 4.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dcim/power-feeds/add. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is known as CVE-2024-40739. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-40741 | Netbox 4.0.3 edit ID cross site scripting
1 year 1 month ago
A vulnerability was found in Netbox 4.0.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /circuits/circuits/{id}/edit/. The manipulation of the argument ID leads to cross site scripting.
This vulnerability is handled as CVE-2024-40741. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-40742 | Netbox 4.0.3 /circuits/circuits/add ID cross site scripting
1 year 1 month ago
A vulnerability was found in Netbox 4.0.3. It has been classified as problematic. This affects an unknown part of the file /circuits/circuits/add. The manipulation of the argument ID leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-40742. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-38385 | JupiterX Core Plugin up to 3.3.0 on WordPress authorization
1 year 1 month ago
A vulnerability was found in JupiterX Core Plugin up to 3.3.0 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2023-38385. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-20059 | MediaTek MT8390 Da faults that lead to instruction skips (ALPS08541749)
1 year 1 month ago
A vulnerability was found in MediaTek MT6580, MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT6989, MT8188, MT8370 and MT8390 and classified as problematic. This issue affects some unknown processing of the component Da. The manipulation leads to improper handling of faults that lead to instruction skips.
The identification of this vulnerability is CVE-2024-20059. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-39063 | Lime Survey up to 6.5.12 POST Request YII_CSRF_TOKEN cross-site request forgery
1 year 1 month ago
A vulnerability classified as problematic was found in Lime Survey up to 6.5.12. Affected by this vulnerability is an unknown functionality of the component POST Request Handler. The manipulation of the argument YII_CSRF_TOKEN leads to cross-site request forgery.
This vulnerability is known as CVE-2024-39063. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-27183 | dj-extensions DJ-HelpfulArticles up to 1.1.0 on Joomla cross site scripting
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in dj-extensions DJ-HelpfulArticles up to 1.1.0 on Joomla. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-27183. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-43096 | Google Android 12/12L/13/14/15 gatt_sr.cc build_read_multi_rsp out-of-bounds write
1 year 1 month ago
A vulnerability, which was classified as critical, was found in Google Android 12/12L/13/14/15. This affects the function build_read_multi_rsp of the file gatt_sr.cc. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2024-43096. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-24159 | Apple macOS behavioral workflow (Nessus ID 214661)
1 year 1 month ago
A vulnerability, which was classified as critical, was found in Apple macOS. This affects an unknown part. The manipulation leads to enforcement of behavioral workflow.
This vulnerability is uniquely identified as CVE-2025-24159. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24159 | Apple visionOS behavioral workflow (Nessus ID 214661)
1 year 1 month ago
A vulnerability has been found in Apple visionOS and classified as critical. This vulnerability affects unknown code. The manipulation leads to enforcement of behavioral workflow.
This vulnerability was named CVE-2025-24159. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24159 | Apple tvOS behavioral workflow (Nessus ID 214661)
1 year 1 month ago
A vulnerability was found in Apple tvOS and classified as critical. This issue affects some unknown processing. The manipulation leads to enforcement of behavioral workflow.
The identification of this vulnerability is CVE-2025-24159. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24109 | Apple macOS up to 13.6/14.6/15.2 downgrade (Nessus ID 214660)
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in Apple macOS up to 13.6/14.6/15.2. Affected by this issue is some unknown functionality. The manipulation leads to algorithm downgrade.
This vulnerability is handled as CVE-2025-24109. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
ChatGPT 漏洞遭超一万个 IP 地址主动利用,美国政府机构惨遭攻击
1 year 1 month ago
安全客
Krijgsmacht krijgt vernieuwde drones
1 year 1 month ago
De mini-UAS (unmanned aerial systems) van Defensie zijn aan het einde van hun levensduur. Daarom gaat de Amerikaanse leverancier AeroVironment deze Puma-drones vernieuwen. Ze worden nog dit jaar geleverd en zijn straks inzetbaar op verschillende niveaus binnen de hele krijgsmacht.