Latest CVE Feed
-
8.7
HIGHCVE-2024-38644
An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Sta... Read more
Affected Products : notes_station_3- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
9.3
CRITICALCVE-2024-38643
A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerabilit... Read more
Affected Products : notes_station_3- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-37050
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have alre... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-37049
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have alre... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-37048
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We ... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-37047
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have alre... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
2.1
LOWCVE-2024-37046
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensit... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-37045
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We ... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-37044
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have alre... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-37043
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensit... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-37042
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We ... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-37041
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have alre... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
6.3
MEDIUMCVE-2024-32770
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the follow... Read more
Affected Products : photo_station- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
6.3
MEDIUMCVE-2024-32769
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the follow... Read more
Affected Products : photo_station- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
6.3
MEDIUMCVE-2024-32768
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the follow... Read more
Affected Products : photo_station- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
6.3
MEDIUMCVE-2024-32767
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the follow... Read more
Affected Products : photo_station- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-10863
: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: from 10.1 before <24.4. End-users can potentially exploit the vulnerability to exclude audit tra... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
9.8
CRITICALCVE-2023-24467
Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.... Read more
Affected Products : imanager- Published: Nov. 22, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2023-24466
Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.... Read more
Affected Products : imanager- Published: Nov. 22, 2024
- Modified: Apr. 10, 2025
-
7.6
HIGHCVE-2022-26324
Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.... Read more
Affected Products : imanager- Published: Nov. 22, 2024
- Modified: Apr. 10, 2025