Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-19 CVE-2024-43496 Unspecified vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
network
low complexity
microsoft
8.8
2024-09-19 CVE-2024-9003 Unspecified vulnerability in Jflow Project Jflow 2.0.0
A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0.
network
low complexity
jflow-project
5.3
2024-09-19 CVE-2024-9004 OS Command Injection vulnerability in Dlink Dar-7000 Firmware
A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912.
network
low complexity
dlink CWE-78
critical
9.8
2024-09-19 CVE-2024-9001 OS Command Injection vulnerability in Totolink T10 Firmware 4.1.8Cu.5207
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207.
network
low complexity
totolink CWE-78
8.8
2024-09-19 CVE-2024-25673 Injection vulnerability in Couchbase Server
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
network
low complexity
couchbase CWE-74
6.1
2024-09-19 CVE-2024-33109 Path Traversal vulnerability in multiple products
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
network
low complexity
ergophone yealink CWE-22
critical
9.8
2024-09-19 CVE-2024-40125 Unrestricted Upload of File with Dangerous Type vulnerability in Closed-Loop Cless Server 4.5.2
An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.
network
low complexity
closed-loop CWE-434
critical
9.8
2024-09-19 CVE-2024-47159 Incorrect Authorization vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
network
low complexity
jetbrains CWE-863
4.3
2024-09-19 CVE-2024-47160 Incorrect Authorization vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
network
low complexity
jetbrains CWE-863
5.3
2024-09-19 CVE-2024-47162 Insufficiently Protected Credentials vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
network
low complexity
jetbrains CWE-522
5.3