NA - CVE-2024-39926 - An issue was discovered in Vaultwarden...
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin...
NA - CVE-2024-3100 - A potential buffer overflow vulnerability was...
A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.
Medium - CVE-2024-45101 - A privilege escalation vulnerability was...
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can...
Medium - CVE-2024-45104 - A valid, authenticated LXCA user without...
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
Medium - CVE-2024-45105 - An internal product security audit discovered a...
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to...
Medium - CVE-2024-4550 - A potential buffer overflow vulnerability was...
A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.
Medium - CVE-2024-7756 - A potential vulnerability was reported in the...
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.
High - CVE-2024-8278 - A privilege escalation vulnerability was...
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.