NA - CVE-2024-47531 - Scout is a web-based visualizer for VCF-files....
Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any...
NA - CVE-2024-47532 - RestrictedPython is a restricted execution...
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj...
NA - CVE-2024-46540 - A remote code execution (RCE) vulnerability in...
A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload...
NA - CVE-2024-46548 - TP-Link Tapo P125M and Kasa KP125M v1.0.3 was...
TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a...
NA - CVE-2024-46549 - An issue in the TP-Link MQTT Broker and API...
An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by other users.
NA - CVE-2024-47536 - Citizen is a MediaWiki skin that makes...
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their...
NA - CVE-2024-9158 - A stored cross site scripting vulnerability...
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
NA - CVE-2024-28809 - An issue was discovered in Infinera hiT 7300...
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded...
NA - CVE-2024-35495 - An Information Disclosure vulnerability in the...
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing...