NA - CVE-2024-46316 - DrayTek Vigor3900 v1.5.1.6 was discovered to...
DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute...
NA - CVE-2024-42988 - Lack of access control in ChallengeSolves...
Lack of access control in ChallengeSolves (/api/v1/challenges//solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, regardless of...
High - CVE-2024-43610 - Exposure of Sensitive Information to an...
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
NA - CVE-2024-45746 - An issue was discovered in Trusted Firmware-M...
An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) and output arguments (out_vec)....
NA - CVE-2024-9463 - An OS command injection vulnerability in Palo...
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames,...
NA - CVE-2024-9464 - An OS command injection vulnerability in Palo...
An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames,...
NA - CVE-2024-9465 - An SQL injection vulnerability in Palo Alto...
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations,...
NA - CVE-2024-9466 - A cleartext storage of sensitive information...
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using...
NA - CVE-2024-9467 - A reflected XSS vulnerability in Palo Alto...
A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a...