Böngésszen szolgáltatóknak szóló tartalmaink között.
2024. jún. 14.
Riasztás
NA - CVE-2024-33377 - LB-LINK BL-W1210M v2.0 was discovered to...
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with...
NA - CVE-2024-34539 - Hardcoded credentials in TerraMaster TOS...
Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the...
NA - CVE-2024-34694 - LNbits is a Lightning wallet and accounts...
LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it...
NA - CVE-2024-37312 - user_oidc app is an OpenID Connect user backend...
user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is...
NA - CVE-2024-37313 - Nextcloud server is a self hosted personal...
Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is...
NA - CVE-2024-37314 - Nextcloud Photos is a photo management app....
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud...
NA - CVE-2024-37367 - A user authentication vulnerability exists in...
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s...
NA - CVE-2024-37368 - A user authentication vulnerability exists in...
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s...
NA - CVE-2024-37644 - TRENDnet TEW-814DAP v1_(FW1.01B01) was...
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.