Lucene search

K

Toshiba Electronic Devices & Storage Corporation Security Vulnerabilities

vulnrichment
vulnrichment

CVE-2023-3940 Multiple arbitrary file reads in ZkTeco-based OEM devices

Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to access any file on the system. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0 and possibly...

7.5CVSS

7.1AI Score

0.0004EPSS

2024-05-21 10:15 AM
1
debiancve
debiancve

CVE-2024-38619

In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Check whether the media is initialized The member "uzonesize" of struct alauda_info will remain 0 if alauda_init_media() fails, potentially causing divide errors in alauda_read_data() and alauda_write_lba()....

6.6AI Score

0.0004EPSS

2024-06-20 07:15 AM
3
osv
osv

CVE-2022-32081

MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at...

7.5CVSS

2.1AI Score

0.003EPSS

2022-07-01 08:15 PM
13
nessus
nessus

RHEL 7 : OpenShift Container Storage 3.11.z (RHSA-2022:0308)

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2022:0308 advisory. The OpenShift Container Storage solution provides persistent storage service for OpenShift Containers and OpenShift Infrastructure...

6.5CVSS

7.8AI Score

0.014EPSS

2022-01-28 12:00 AM
10
ibm
ibm

Security Bulletin: A vulnerability in Transparent Cloud Tiering affects IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products

Summary A vulnerability in netty-codec-http affects the Transparent Cloud Tiering function in IBM Storage Virtualize products. Most systems do not have Transparent Cloud Tiering configured. You can confirm by running the lsvolumebackup CLI command - if there is no output, then this feature is not.....

5.3CVSS

6AI Score

0.0004EPSS

2024-06-19 10:43 AM
6
osv
osv

CVE-2023-44008

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager...

9.8CVSS

8.1AI Score

0.003EPSS

2023-10-02 09:15 PM
5
nessus
nessus

RHEL 9 : Red Hat Ceph Storage 6.1 (RHSA-2023:3623)

The remote Redhat Enterprise Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:3623 advisory. Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage...

7.5CVSS

7.4AI Score

0.003EPSS

2023-06-15 12:00 AM
9
nessus
nessus

RHEL 7 : Red Hat Ceph Storage 3.3 (RHSA-2020:3504)

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by a vulnerability as referenced in the RHSA-2020:3504 advisory. Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with...

6.5CVSS

6.8AI Score

0.003EPSS

2020-08-18 12:00 AM
51
ubuntucve
ubuntucve

CVE-2024-38619

In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Check whether the media is initialized The member "uzonesize" of struct alauda_info will remain 0 if alauda_init_media() fails, potentially causing divide errors in alauda_read_data() and alauda_write_lba(). -....

7AI Score

0.0004EPSS

2024-06-20 12:00 AM
cvelist
cvelist

CVE-2024-4232 Password Storage in Plaintext Vulnerability in Digisol Router

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and...

6.8AI Score

0.0004EPSS

2024-05-10 01:32 PM
cvelist
cvelist

CVE-2023-3941 Multiple arbitrary file writes in ZkTeco-based OEM devices

Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system with root privileges. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the...

10CVSS

9.7AI Score

0.0004EPSS

2024-05-21 10:20 AM
nuclei
nuclei

Zabbix - SAML SSO Authentication Bypass

When SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor because a user login stored in the session was not...

9.8CVSS

9.4AI Score

0.97EPSS

2022-02-20 12:37 PM
72
vulnrichment
vulnrichment

CVE-2024-4232 Password Storage in Plaintext Vulnerability in Digisol Router

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and...

6.9AI Score

0.0004EPSS

2024-05-10 01:32 PM
1
cvelist
cvelist

CVE-2024-22385 File and Directory Permission Vulnerability in Hitachi Storage Provider for VMware vCenter

Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before...

4.4CVSS

0.0004EPSS

2024-06-25 01:34 AM
3
cvelist

7CVSS

7.9AI Score

0.0004EPSS

2022-10-11 12:00 AM
2
vulnrichment
vulnrichment

CVE-2024-38329 IBM Storage Protect for Virtual Environments: Data Protection for VMware security bypass

IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a specially crafted request, an attacker could exploit this...

7.7CVSS

7.2AI Score

0.0004EPSS

2024-06-19 01:43 PM
1
osv
osv

CVE-2023-5910

A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing of the file install.php of the component Web Config. The manipulation of the argument Site Title with the input alert(1) leads to cross site scripting. The attack may be initiated....

6.1CVSS

6.1AI Score

0.001EPSS

2023-11-02 12:15 AM
2
osv
osv

CVE-2023-46742

CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the logs in multiple components. When CubeCS creates new users, it leaks the users secret key. This could allow a lower-privileged user with access to the....

6.5CVSS

6.3AI Score

0.0005EPSS

2024-01-03 05:15 PM
2
cvelist

5.5CVSS

7.6AI Score

0.0004EPSS

2021-12-15 02:15 PM
1
cvelist

4.7CVSS

5.5AI Score

0.0005EPSS

2022-07-12 10:37 PM
1
veeam
veeam

Dell PowerPath - Veeam Agent for Linux Limitations

If a Linux server has Dell PowerPath devices attached, all the underlying block devices representing the network paths to the server are skipped from processing. This will result in the error "No objects to backup" or PowerPath devices missing from the backup. If non-PowerPath devices are part of.....

7.1AI Score

2018-09-19 12:00 AM
8
osv
osv

BIT-vault-2024-0831

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the log_raw option, which may log sensitive information to other audit devices, regardless of whether they are configured to use...

6.5CVSS

6.7AI Score

0.001EPSS

2024-03-06 11:07 AM
8
osv
osv

BIT-gitlab-2024-4201

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as...

4.4CVSS

4.2AI Score

0.0004EPSS

2024-06-17 07:20 AM
174
githubexploit

5.5CVSS

5.4AI Score

0.0004EPSS

2024-02-01 02:29 AM
44
githubexploit
githubexploit

Exploit for Improper Check for Unusual or Exceptional Conditions in Apple Ipados

CVE-2023-41993 PoC exploit for CVE-2023-41993. It's written...

9.8CVSS

9.4AI Score

0.003EPSS

2023-10-15 12:14 PM
530
nessus
nessus

RHEL 7 : Red Hat Ceph Storage (RHSA-2019:4353)

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by a vulnerability as referenced in the RHSA-2019:4353 advisory. Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with...

6.5CVSS

6.6AI Score

0.001EPSS

2019-12-24 12:00 AM
136
vulnrichment
vulnrichment

CVE-2024-22385 File and Directory Permission Vulnerability in Hitachi Storage Provider for VMware vCenter

Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before...

4.4CVSS

6.9AI Score

0.0004EPSS

2024-06-25 01:34 AM
1
cvelist
cvelist

CVE-2024-38329 IBM Storage Protect for Virtual Environments: Data Protection for VMware security bypass

IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a specially crafted request, an attacker could exploit this...

7.7CVSS

0.0004EPSS

2024-06-19 01:43 PM
4
cvelist

5.5CVSS

7.6AI Score

0.0004EPSS

2021-12-15 02:15 PM
1
nessus
nessus

Seagate Exos X SLP Detection

The remote host indicates that it is a Seagate Exos X SAN via its SLP attribute...

7AI Score

2023-08-09 12:00 AM
6
nuclei
nuclei

Nacos <1.4.1 - Authentication Bypass

Nacos before version 1.4.1 is vulnerable to authentication bypass because the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is....

8.6CVSS

8.8AI Score

0.968EPSS

2021-04-28 05:01 AM
6
vulnrichment
vulnrichment

CVE-2024-1628 OS command injection vulnerabilities in GE HealthCare ultrasound devices

OS command injection vulnerabilities in GE HealthCare ultrasound...

8.4CVSS

7.8AI Score

0.0004EPSS

2024-05-14 04:04 PM
cvelist
cvelist

CVE-2023-3940 Multiple arbitrary file reads in ZkTeco-based OEM devices

Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to access any file on the system. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0 and possibly...

7.5CVSS

7.7AI Score

0.0004EPSS

2024-05-21 10:15 AM
veeam
veeam

How to Connect to an Object Storage Repository via Azure Blob Private Endpoints

This article documents how to use Azure Blob Storage Account private endpoints (via Azure VPN or Azure ExpressRoute) for offload or to connect to an Object Storage Repository in Veeam Backup & Replication 12 or...

7.1AI Score

2023-01-10 12:00 AM
14
cvelist
cvelist

CVE-2024-26881 net: hns3: fix kernel crash when 1588 is received on HIP08 devices

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when 1588 is received on HIP08 devices The HIP08 devices does not register the ptp devices, so the hdev-&gt;ptp is NULL, but the hardware can receive 1588 messages, and set the HNS3_RXD_TS_VLD_B bit, so,...

5.5AI Score

0.0004EPSS

2024-04-17 10:27 AM
1
nessus
nessus

RHEL 7 / 8 : Red Hat Ceph Storage 4.1 (RHSA-2020:5325)

The remote Redhat Enterprise Linux 7 / 8 host has packages installed that are affected by a vulnerability as referenced in the RHSA-2020:5325 advisory. Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system...

8.8CVSS

8.7AI Score

0.001EPSS

2020-12-02 12:00 AM
20
vulnrichment
vulnrichment

CVE-2021-47517 ethtool: do not perform operations on net devices being unregistered

In the Linux kernel, the following vulnerability has been resolved: ethtool: do not perform operations on net devices being unregistered There is a short period between a net device starts to be unregistered and when it is actually gone. In that time frame ethtool operations could still be...

6.8AI Score

0.0004EPSS

2024-05-24 03:09 PM
osv
osv

CVE-2024-4201

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as...

4.4CVSS

6AI Score

0.0004EPSS

2024-06-12 11:15 PM
1
ubuntucve
ubuntucve

CVE-2021-47583

In the Linux kernel, the following vulnerability has been resolved: media: mxl111sf: change mutex_init() location Syzbot reported, that mxl111sf_ctrl_msg() uses uninitialized mutex. The problem was in wrong mutex_init() location. Previous mutex_init(&state-&gt;msg_lock) call was in -&gt;init() func...

7AI Score

0.0004EPSS

2024-06-20 12:00 AM
1
osv
osv

CVE-2022-1305

Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

8.8CVSS

9.5AI Score

0.004EPSS

2022-07-25 02:15 PM
1
vulnrichment
vulnrichment

CVE-2024-25142 Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache...

6.3AI Score

0.0004EPSS

2024-06-14 08:25 AM
1
osv
osv

CVE-2023-28434

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing PostPolicyBucket. To carry out this attack, the attacker requires credentials with....

8.8CVSS

8.8AI Score

0.062EPSS

2023-03-22 09:15 PM
7
githubexploit
githubexploit

Exploit for CVE-2023-46453

GL.iNet Router Authentication Bypass (CVE-2023-46453) Exploit...

7.7AI Score

2024-03-07 08:05 AM
232
cvelist
cvelist

CVE-2021-47517 ethtool: do not perform operations on net devices being unregistered

In the Linux kernel, the following vulnerability has been resolved: ethtool: do not perform operations on net devices being unregistered There is a short period between a net device starts to be unregistered and when it is actually gone. In that time frame ethtool operations could still be...

6.4AI Score

0.0004EPSS

2024-05-24 03:09 PM
nessus
nessus

RHEL 8 / 9 : Red Hat Ceph Storage 6.1 (RHSA-2024:2631)

The remote Redhat Enterprise Linux 8 / 9 host has packages installed that are affected by a vulnerability as referenced in the RHSA-2024:2631 advisory. Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system...

9.8CVSS

6AI Score

0.002EPSS

2024-05-01 12:00 AM
5
cvelist
cvelist

CVE-2024-25142 Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache...

0.0004EPSS

2024-06-14 08:25 AM
1
cvelist
cvelist

CVE-2023-27370 NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability

NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability,...

5.7CVSS

5.4AI Score

0.0005EPSS

2024-05-03 01:56 AM
debiancve
debiancve

CVE-2021-47583

In the Linux kernel, the following vulnerability has been resolved: media: mxl111sf: change mutex_init() location Syzbot reported, that mxl111sf_ctrl_msg() uses uninitialized mutex. The problem was in wrong mutex_init() location. Previous mutex_init(&state-&gt;msg_lock) call was in -&gt;init()...

7AI Score

0.0004EPSS

2024-06-19 03:15 PM
Total number of security vulnerabilities113787