NA - CVE-2024-47169 - Agnai is an artificial-intelligence-agnostic...
Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to...
NA - CVE-2024-47170 - Agnai is an artificial-intelligence-agnostic...
Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at...
NA - CVE-2024-47171 - Agnai is an artificial-intelligence-agnostic...
Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload image files at attacker-chosen...
NA - CVE-2024-47174 - Nix is a package manager for Linux and other...
Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `` did not verify TLS certificates on HTTPS connections. This could lead...
NA - CVE-2024-8118 - In Grafana, the wrong permission is applied to...
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.
NA - CVE-2024-46628 - Tenda G3 Router firmware v15.03.05.05 was...
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.
NA - CVE-2024-47179 - RSSHub is an RSS network. Prior to commit...
RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Poisoning, which could have lead to a full repository takeover. Downstream...
NA - CVE-2024-47180 - Shields.io is a service for concise,...
Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-hosting their own instance of shields using version < `server-2024-09-25` are...
NA - CVE-2024-7594 - Vault’s SSH secrets engine did not require the...
Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not...