Latest CVE Feed
-
7.5
HIGHCVE-2024-41903
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's... Read more
Affected Products : sinec_traffic_analyzer- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
6.9
MEDIUMCVE-2024-41683
A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a strong user password policy. This could facilitate a brute force attack against legitimate user passwords.... Read more
Affected Products : location_intelligence- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
6.9
MEDIUMCVE-2024-41682
A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated remote attacker to conduct brute fo... Read more
Affected Products : location_intelligence- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
7.5
HIGHCVE-2024-41681
A vulnerability has been identified in Location Intelligence family (All versions < V4.4). The web server of affected products is configured to support weak ciphers by default. This could allow an unauthenticated attacker in an on-path position to to rea... Read more
Affected Products : location_intelligence- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
8.5
HIGHCVE-2024-36398
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileges.... Read more
Affected Products : sinec_nms- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
7.8
HIGHCVE-2024-41864
Substance3D - Designer versions 13.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim... Read more
Affected Products : substance_3d_designer- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
5.5
MEDIUMCVE-2024-41863
Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this is... Read more
Affected Products : substance_3d_sampler- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
5.5
MEDIUMCVE-2024-41862
Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this is... Read more
Affected Products : substance_3d_sampler- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
5.5
MEDIUMCVE-2024-41861
Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this is... Read more
Affected Products : substance_3d_sampler- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
5.5
MEDIUMCVE-2024-41860
Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this is... Read more
Affected Products : substance_3d_sampler- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
7.8
HIGHCVE-2024-38153
Windows Kernel Elevation of Privilege Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +10 more products- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
7.8
HIGHCVE-2024-38152
Windows OLE Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +10 more products- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
5.5
MEDIUMCVE-2024-38151
Windows Kernel Information Disclosure Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +10 more products- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
7.8
HIGHCVE-2024-38150
Windows DWM Core Library Elevation of Privilege Vulnerability... Read more
- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
6.1
MEDIUMCVE-2024-41613
A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note.... Read more
Affected Products : symphony_cms- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
5.3
MEDIUMCVE-2024-41941
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and modify settings in the application without... Read more
Affected Products : sinec_nms- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
9.4
CRITICALCVE-2024-41940
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privilege... Read more
Affected Products : sinec_nms- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
8.8
HIGHCVE-2024-41939
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and elevate their privileges on the applicatio... Read more
Affected Products : sinec_nms- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
5.5
MEDIUMCVE-2024-41938
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The importCertificate function of the SINEC NMS Control web application contains a path traversal vulnerability. This could allow an authenticated attacker it to delete arbitrary cert... Read more
Affected Products : sinec_nms- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
5.4
MEDIUMCVE-2024-41907
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to c... Read more
Affected Products : sinec_traffic_analyzer- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024