Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-27 CVE-2024-39275 Unspecified vulnerability in Advantech Adam-5630 Firmware
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed.
network
low complexity
advantech
8.8
2024-09-27 CVE-2024-9301 Path Traversal vulnerability in Netflix E2Nest
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
network
low complexity
netflix CWE-22
7.5
2024-09-27 CVE-2024-8630 SQL Injection vulnerability in Alisonic Sibylla Firmware
Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.
network
low complexity
alisonic CWE-89
critical
9.8
2024-09-27 CVE-2024-40510 Cross-site Scripting vulnerability in Openpetra 2023.02
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMCommon.asmx function.
network
low complexity
openpetra CWE-79
8.2
2024-09-27 CVE-2024-44910 Out-of-bounds Read vulnerability in Nasa Cryptolib 1.3.0
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).
network
low complexity
nasa CWE-125
7.5
2024-09-27 CVE-2024-44911 Out-of-bounds Read vulnerability in Nasa Cryptolib 1.3.0
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_aos.c).
network
low complexity
nasa CWE-125
7.5
2024-09-27 CVE-2024-44912 Out-of-bounds Read vulnerability in Nasa Cryptolib 1.3.0
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).
network
low complexity
nasa CWE-125
7.5
2024-09-27 CVE-2024-47182 Inadequate Encryption Strength vulnerability in Amirraminfar Dozzle
Dozzle is a realtime log viewer for docker containers.
network
low complexity
amirraminfar CWE-326
7.5
2024-09-27 CVE-2024-47184 Cross-site Scripting vulnerability in Ampache
Ampache is a web based audio/video streaming application and file manager.
network
low complexity
ampache CWE-79
4.8
2024-09-27 CVE-2024-7149 Path Traversal vulnerability in Themewinter Eventin
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters.
network
low complexity
themewinter CWE-22
8.8