Latest CVE Feed
-
4.3
MEDIUMCVE-2024-8059
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
8.8
HIGHCVE-2024-43099
The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to maintain security. However, if an attacker captures this s... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
7.2
HIGHCVE-2024-8281
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
6.8
MEDIUMCVE-2024-7756
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
7.2
HIGHCVE-2024-8280
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
6.7
MEDIUMCVE-2024-4550
A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
7.2
HIGHCVE-2024-8278
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
7.2
HIGHCVE-2024-8279
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
6.7
MEDIUMCVE-2024-3100
A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
6.7
MEDIUMCVE-2024-45105
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
6.8
MEDIUMCVE-2024-45101
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.... Read more
Affected Products : xclarity_administrator- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
7.5
HIGHCVE-2024-7928
A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The a... Read more
Affected Products : fastadmin- Published: Aug. 19, 2024
- Modified: Sep. 13, 2024
-
9.8
CRITICALCVE-2024-43931
Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.... Read more
Affected Products : jobsearch_wp_job_board- Published: Aug. 29, 2024
- Modified: Sep. 13, 2024
-
8.8
HIGHCVE-2023-34974
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. QuTScloud, QVR, QES are not affected. We have already fixed the... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 13, 2024
-
9.3
CRITICALCVE-2024-42037
Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Aug. 08, 2024
- Modified: Sep. 13, 2024
-
8.2
HIGHCVE-2024-32762
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuLog Center... Read more
Affected Products : qulog_center- Published: Sep. 06, 2024
- Modified: Sep. 13, 2024
-
7.5
HIGHCVE-2024-42036
Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Aug. 08, 2024
- Modified: Sep. 13, 2024
-
9.8
CRITICALCVE-2024-43132
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This issue affects Docket (WooCommerce Collections / Wishlist / ... Read more
Affected Products : docket- Published: Aug. 29, 2024
- Modified: Sep. 13, 2024
-
4.8
MEDIUMCVE-2024-27125
A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following ver... Read more
Affected Products : helpdesk- Published: Sep. 06, 2024
- Modified: Sep. 13, 2024
-
7.6
HIGHCVE-2024-39658
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking System Salon booking system allows SQL Injection.This issue affects Salon booking system: from n/a through 10.7.... Read more
Affected Products : salon_booking_system- Published: Aug. 29, 2024
- Modified: Sep. 13, 2024