NA - CVE-2024-7293 - In Progress® Telerik® Report Server versions...
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
NA - CVE-2024-7294 - In Progress® Telerik® Report Server versions...
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
NA - CVE-2024-7840 - In Progress Telerik Reporting versions prior to...
In Progress Telerik Reporting versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
NA - CVE-2024-8014 - In Progress Telerik Reporting versions prior to...
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
NA - CVE-2024-8015 - In Progress Telerik Report Server versions...
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
NA - CVE-2024-8048 - In Progress Telerik Reporting versions prior to...
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
Medium - CVE-2024-9671 - A vulnerability was found in 3Scale. There is...
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.
Medium - CVE-2024-9675 - A vulnerability was found in Buildah. Cache...
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file...
NA - CVE-2024-25825 - FydeOS for PC 17.1 R114, FydeOS for VMware 17.0...
FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers...