NA - CVE-2024-9014 - pgAdmin versions 8.11 and earlier are...
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to...
NA - CVE-2023-46948 - A reflected Cross-Site Scripting (XSS)...
A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the...
NA - CVE-2024-0001 - A condition exists in FlashArray Purity whereby...
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
NA - CVE-2024-0003 - A condition exists in FlashArray Purity whereby...
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
NA - CVE-2024-0004 - A condition exists in FlashArray Purity whereby...
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
NA - CVE-2024-0005 - A condition exists in FlashArray and FlashBlade...
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.
NA - CVE-2024-39341 - Entrust Instant Financial Issuance (On Premise)...
Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml)...
NA - CVE-2024-39342 - Entrust Instant Financial Issuance (formerly...
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process...
NA - CVE-2024-39842 - A SQL injection vulnerability in Centreon...
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.