NA - CVE-2024-12672 - A third-party vulnerability exists in the...
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor...
NA - CVE-2024-12727 - A pre-auth SQL injection vulnerability in the...
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code...
NA - CVE-2024-12729 - A post-auth code injection vulnerability in the...
A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).
NA - CVE-2024-2201 - A cross-privilege Spectre v2 vulnerability...
A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems.
NA - CVE-2024-12700 - There is an unrestricted file upload...
There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code with the privileges of user running the...
NA - CVE-2024-54009 - Remote authentication bypass vulnerability in...
Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.