NA - CVE-2024-31415 - The Eaton Foreseer software provides the...
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption...
NA - CVE-2024-31416 - The Eaton Foreseer software provides multiple...
The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the...
NA - CVE-2024-43099 - The session hijacking attack targets the...
The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is...
NA - CVE-2024-45368 - The H2-DM1E PLC's authentication protocol...
The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response protocol. However, there's an observed anomaly in the H2-DM1E...
NA - CVE-2024-6087 - An improper access control vulnerability exists...
An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the auth tokens issued by the...
NA - CVE-2024-6582 - A broken access control vulnerability exists in...
A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and...
NA - CVE-2024-6862 - A Cross-Site Request Forgery (CSRF)...
A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up for and create...
NA - CVE-2024-6867 - An information disclosure vulnerability exists...
An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access...
NA - CVE-2024-39924 - An issue was discovered in Vaultwarden...
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering...
NA - CVE-2024-39925 - An issue was discovered in Vaultwarden...
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated...