Medium - CVE-2024-39527 - An Exposure of Sensitive Information to an...
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged...
Medium - CVE-2024-39534 - An Incorrect Comparison vulnerability in the...
An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send...
Medium - CVE-2024-39544 - An Incorrect Default Permissions vulnerability...
An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved allows a low privileged local attacker to view NETCONF traceoptions files,...
High - CVE-2024-39547 - An Improper Handling of Exceptional Conditions...
An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based attacker sending...
NA - CVE-2024-39563 - A Command Injection vulnerability in Juniper...
A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the...
NA - CVE-2024-42640 - angular-base64-upload prior to v0.1.21 is...
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to...
NA - CVE-2024-44729 - Incorrect access control in the component...
Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.
NA - CVE-2024-44730 - Incorrect access control in the function...
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
NA - CVE-2024-46088 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute...
Medium - CVE-2024-47489 - An Improper Handling of Exceptional Conditions...
An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network...