Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-41324
Northern.tech Mender 3.3.x prior to 3.3.2 and 3.4.x prior to 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.
NA
CVE-2024-37343
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is then temporarily stored wher...
NA
CVE-2024-37344
There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the policy management UI when the administrat...
NA
CVE-2024-37345
There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can access it. The scope is uncha...
NA
CVE-2024-37346
There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access before 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid dat...
NA
CVE-2024-37347
There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access before 13.06. Attackers with system administrator permissions can pass a limited length script to be run by another administrator. The scope is unchang...
NA
CVE-2024-37348
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the management UI when the second administrator late...
NA
CVE-2024-37626
A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote malicious user to execute arbitrary code via the iface parameter in the vif_enable function.
NA
CVE-2024-28397
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows malicious users to execute arbitrary code via a crafted API call.
1 Github repository
NA
CVE-2024-37676
An issue in htop-dev htop v.2.20 allows a local malicious user to cause an out-of-bounds access in the Header_populateFromSettings function.
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege
CVE-2022-48762
CVE-2022-48751
CVE-2024-37079
CVE-2024-30848
LFI
man-in-the-middle
CVE-2022-48736
CVE-2024-30103
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »