2024-09-10: [CVE-2024-43491] Microsoft Windows Update Remote Code Execution Vulnerability
Microsoft Windows Update contains an unspecified vulnerability that allows for remote code execution. CISA Known Exploited Vulnerabilities Catalog Read More
Портал информационной безопасности
Каталог известных эксплуатируемых уязвимостей
Microsoft Windows Update contains an unspecified vulnerability that allows for remote code execution. CISA Known Exploited Vulnerabilities Catalog Read More
Microsoft Windows Installer contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges. CISA Known Exploited…
Microsoft Publisher contains a security feature bypass vulnerability that allows attacker to bypass Office macro policies used to block untrusted…
Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to…
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may…
ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders.…
Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could…
Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary…
Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download…
Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a…
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context…
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted…
The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or…
Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an…
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution. CISA Known Exploited Vulnerabilities Catalog Read…
Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the…
Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client…
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which…
SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution. CISA Known…
Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.…