Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-12-11 CVE-2024-53289 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Dell Thinos 2408
Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability.
local
high complexity
dell CWE-367
7.0
2024-12-11 CVE-2024-53290 Command Injection vulnerability in Dell Thinos 2408
Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability.
local
low complexity
dell CWE-77
8.4
2024-12-11 CVE-2024-53292 Insufficiently Protected Credentials vulnerability in Dell Vxrail Hyperconverged Infrastructure
Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper.
local
low complexity
dell CWE-522
6.7
2024-12-11 CVE-2023-37395 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.
local
low complexity
ibm CWE-327
3.3
2024-12-11 CVE-2024-35117 IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user.
network
high complexity
CWE-312
4.4
2024-12-10 CVE-2024-43712 Cross-site Scripting vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could allow an attacker to execute arbitrary code in the context of the victim's browser.
network
low complexity
adobe CWE-79
5.4
2024-12-10 CVE-2024-43713 Cross-site Scripting vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session.
network
low complexity
adobe CWE-79
5.4
2024-12-10 CVE-2024-43714 Cross-site Scripting vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session.
network
low complexity
adobe CWE-79
5.4
2024-12-10 CVE-2024-43715 Cross-site Scripting vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session.
network
low complexity
adobe CWE-79
5.4
2024-12-10 CVE-2024-43716 Unspecified vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.
network
low complexity
adobe
4.3