Latest critical severity Vulnerabilities

streamlit-geospatial blind SSRF in pages/9_πŸ”²_Vector_Data_Visualization.py
streamlit-geospatial remote code execution in pages/8_🏜️_Raster_Data_Visualization.py
Remote code execution in streamlit geospatial in pages/10_🌍_Earth_Engine_Datasets.py
Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py MODIS Ocean Color SMI option vis_params
Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py MODIS Ocean Color SMI option palette
Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py MODIS Gap filled Land Surface Temperature Daily option
Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py Any Earth Engine ImageCollection option vis_params
Remote code execution in streamlit geospatial in pages/1_πŸ“·_Timelapse.py Any Earth Engine ImageCollection option palette
Softaculous Webuzo Password Reset Command Injection
Softaculous Webuzo FTP Management Command Injection
Softaculous Webuzo Authentication Bypass
In Spring Cloud Data Flow versions prior to 2.11.4,Β Β a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file s...
maven/org.springframework.cloud:spring-cloud-skipper<2.11.4
Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Huawei Emui=14.0.0
Huawei Harmonyos=4.0.0
Huawei Harmonyos=4.2.0
Remote code execution in Spring Cloud Data Flow
maven/org.springframework.cloud:spring-cloud-skipper<2.11.4
itsourcecode Tailoring Management System expcatadd.php sql injection
Tailoring Management System Project Tailoring Management System=1.0
Moby authz zero length regression
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an a...
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.1.0<=9.1.9
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.2.0<=9.2.9
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.3.0<=9.3.2
Arubanetworks Edgeconnect Sd-wan Orchestrator>=9.4.0<=9.4.1
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build...
Acronis Cyber Infrastructure<5.0.1-61
Acronis Cyber Infrastructure>=5.1.1<5.1.1-71
Acronis Cyber Infrastructure>=5.2.1<5.2.1-69
Acronis Cyber Infrastructure>=5.3.1<5.3.1-53
Acronis Cyber Infrastructure>=5.4.4<5.4.4-132
Unsafe Deserialization Vulnerability
Progress Telerik Reporting<18.1.24.709
Progress Telerik Report Server Deserialization
Progress Telerik Report Server<10.1.24.709
CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .
CampCodes Supplier Management System=1.0
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.
Tendacn Fh1201 Firmware=1.2.0.14
Tendacn Fh1201
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traver...
stitionai devika=1.0
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.
Tendacn Fh1201 Firmware=1.2.0.14
Tendacn Fh1201
Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatic.
Tendacn Fh1201 Firmware=1.2.0.14
Tendacn Fh1201
GroupMe Elevation of Privilege Vulnerability
Microsoft GroupMe
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.
Totolink A6000r Firmware=1.0.1-b20201211.2000
TOTOLINK A6000R
Missing Authorization Checks In NI VeriStand Gateway For Project Resources
Execution with Unnecessary Privileges
Hardcoded MSSQL Credentials
Deserialization of Untrusted Data in NI VeriStand Waveform Streaming Server
Deserialization of Untrusted Data in NI VeriStand DataLogging Server
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send maliciou...
pip/anki<24.06
fishaudio/Bert-VITS2 Command Injection in webui_preprocess.py bert_gen function
fishaudio/Bert-VITS2 Command Injection in webui_preprocess.py resample function
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send maliciou...
pip/anki<24.06
All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the β€˜eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary...
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts of the affect...
WordPress formlift plugin <= 7.5.17 - Unauthenticated Blind SQL Injection vulnerability
itsourcecode Tailoring Management System staffcatadd.php sql injection
Tailoring Management System Project Tailoring Management System=1.0
itsourcecode Online Blood Bank Management System Login login.php sql injection
Online Blood Bank Management System Project Online Blood Bank Management System=1.0
Tenda O3 fromVirtualSet stack-based overflow
Tenda O3 Firmware1.0.0.10\(2478\)
Tenda O3=2.0
Tenda O3 fromDhcpSetSer stack-based overflow
Tenda O3 Firmware1.0.0.10\(2478\)
Tenda O3=2.0
Tenda O3 formexeCommand stack-based overflow
Tenda O3 Firmware1.0.0.10\(2478\)
Tenda O3=2.0
ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.
Proton Protonvpn<3.2.10
Microsoft Windows
LibreChat through 0.7.4-rc1 has incorrect access control for message updates. (Work on a fixed version release has started in PR 3363.)
Librechat Librechat<=0.7.3
Librechat Librechat=0.7.4-rc1
LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images. (Work on a fixed version release has started in PR 3363.)
Librechat Librechat<=0.7.3
Librechat Librechat=0.7.4-rc1
Tenda O3 formQosSet stack-based overflow
Tenda O3 Firmware1.0.0.10\(2478\)
Tenda O3=2.0
D-Link - CWE-294: Authentication Bypass by Capture-replay
D-Link - CWE-288: Authentication Bypass Using an Alternate Path or Channel

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
Β© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203