Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-23 CVE-2024-0003 Unspecified vulnerability in Purestorage Purity//Fa
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
network
low complexity
purestorage
7.2
2024-09-23 CVE-2024-0004 Code Injection vulnerability in Purestorage Purity//Fa
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
network
low complexity
purestorage CWE-94
7.2
2024-09-23 CVE-2024-0005 Command Injection vulnerability in Purestorage Purity//Fa
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.
network
low complexity
purestorage CWE-77
8.8
2024-09-23 CVE-2024-46985 XXE vulnerability in Dataease
DataEase is an open source data visualization analysis tool.
network
low complexity
dataease CWE-611
7.5
2024-09-23 CVE-2024-46997 Unspecified vulnerability in Dataease
DataEase is an open source data visualization analysis tool.
network
low complexity
dataease
critical
9.8
2024-09-23 CVE-2024-47066 Server-Side Request Forgery (SSRF) vulnerability in Lobehub Lobe Chat
Lobe Chat is an open-source artificial intelligence chat framework.
network
low complexity
lobehub CWE-918
8.8
2024-09-23 CVE-2024-47068 Cross-site Scripting vulnerability in Rollupjs Rollup
Rollup is a module bundler for JavaScript.
network
low complexity
rollupjs CWE-79
6.1
2024-09-23 CVE-2024-47069 Cross-site Scripting vulnerability in Oveleon Cookiebar
Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website.
network
low complexity
oveleon CWE-79
6.1
2024-09-23 CVE-2024-23922 Insufficient Verification of Data Authenticity vulnerability in Sony Xav-Ax5500 Firmware 1.13
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability.
low complexity
sony CWE-345
6.8
2024-09-23 CVE-2024-23972 Classic Buffer Overflow vulnerability in Sony Xav-Ax5500 Firmware 1.13
Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability.
low complexity
sony CWE-120
6.8