Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-16 CVE-2024-33848 Unspecified vulnerability in Intel Raid web Console
Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via local access.
local
low complexity
intel
5.5
2024-09-16 CVE-2024-34153 Uncontrolled Search Path Element vulnerability in Intel Raid web Console
Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-427
7.8
2024-09-16 CVE-2024-34543 Unspecified vulnerability in Intel Raid web Console
Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel
7.8
2024-09-16 CVE-2024-34545 Unspecified vulnerability in Intel Raid web Console
Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable information disclosure via adjacent access.
low complexity
intel
5.7
2024-09-16 CVE-2024-36247 Unspecified vulnerability in Intel Raid web Console
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacent access.
low complexity
intel
5.7
2024-09-16 CVE-2024-36261 Unspecified vulnerability in Intel Raid web Console
Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.
low complexity
intel
5.7
2024-09-16 CVE-2024-44623 Code Injection vulnerability in SPX Graphics Controller
An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.
network
low complexity
spx CWE-94
critical
9.8
2024-09-16 CVE-2024-8752 Path Traversal vulnerability in Smart-Hmi Webiq 2.15.9
The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.
network
low complexity
smart-hmi CWE-22
7.5
2024-09-16 CVE-2024-38315 Insufficient Session Expiration vulnerability in IBM Aspera Shares 1.10.0/1.9.14
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
network
low complexity
ibm CWE-613
6.5
2024-09-16 CVE-2024-39772 Unspecified vulnerability in Mattermost Desktop
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
network
low complexity
mattermost
5.3