NA - CVE-2024-47536 - Citizen is a MediaWiki skin that makes...
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their...
NA - CVE-2024-9158 - A stored cross site scripting vulnerability...
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
NA - CVE-2024-28809 - An issue was discovered in Infinera hiT 7300...
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded...
NA - CVE-2024-35495 - An Information Disclosure vulnerability in the...
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing...
NA - CVE-2024-42017 - An issue was discovered in Atos Eviden iCare...
An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows...
NA - CVE-2024-46511 - LoadZilla LLC LoadLogic v1.4.3 was discovered...
LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attacker to execute arbitrary code via the LogicLoadEc2DeployLambda and...
NA - CVE-2024-46635 - An issue in the API endpoint...
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber...
NA - CVE-2024-28810 - An issue was discovered in Infinera hiT 7300...
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by...
NA - CVE-2024-28811 - An issue was discovered in Infinera hiT 7300...
An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.
NA - CVE-2024-28812 - An issue was discovered in Infinera hiT 7300...
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating...