Latest CVE Feed
-
4.9
MEDIUMCVE-2024-45738
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splunk Enterprise `REST_Calls` log channel at the DEBUG loggi... Read more
Affected Products : splunk- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
4.9
MEDIUMCVE-2024-45739
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log channel at... Read more
Affected Products : splunk- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
5.4
MEDIUMCVE-2024-45740
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through Scheduled Views that could result i... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
5.4
MEDIUMCVE-2024-45741
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom conf... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
8.0
HIGHCVE-2024-45731
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows Syst... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
7.1
HIGHCVE-2024-45732
In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles cou... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
8.2
HIGHCVE-2024-9466
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024
-
9.3
CRITICALCVE-2024-9464
An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API ke... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024
-
5.3
MEDIUMCVE-2024-47044
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Oct. 17, 2024
-
8.8
HIGHCVE-2024-45733
In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-45734
In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk classic dashboards. ... Read more
Affected Products : splunk- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-45735
In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged user that does not hold the "admin" or "power" Splunk roles can see App Key Value ... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
6.5
MEDIUMCVE-2024-45736
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-45737
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of Ap... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
8.7
HIGHCVE-2024-39516
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2024-9894
A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file reset.php. The manipulation of the argument useremail leads to sql injection. It is possible to launch the att... Read more
- Published: Oct. 12, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2024-9905
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /admin/?page=inventory/view_inventory&id=2. The manipulation of the argument id leads to sq... Read more
Affected Products : online_eyewear_shop- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
5.4
MEDIUMCVE-2024-9906
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /admin/?page=inventory/view_inventory&id=2. The manipulation of the argument Code leads to cross site sc... Read more
Affected Products : online_eyewear_shop- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-9916
A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection. Th... Read more
Affected Products : usualtoolcms- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2024-9983
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.... Read more
Affected Products : enterprise_cloud_database- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024