Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2024
D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default.
CVSS Score
6.1
EPSS Score
0.012
Published
2024-09-10
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.
CVSS Score
4.8
EPSS Score
0.007
Published
2024-09-10
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
CVSS Score
9.8
EPSS Score
0.002
Published
2024-09-10
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
CVSS Score
4.6
EPSS Score
0.065
Published
2024-09-10
Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client rather than failing authentication due to a PIN validation error. The pairing attempt fails due to the incorrect PIN, but the certificate from the forged pairing attempt is incorrectly persisted prior to the completion of the pairing request. This allows access to the certificate belonging to the attacker.
CVSS Score
6.5
EPSS Score
0.003
Published
2024-09-10
Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Remote user-controlled data tags can reach a Unicode normalization with a compatibility form NFKD. Under Windows, such normalization is costly in resources and may lead to denial of service with attacks such as One Million Unicode payload. This can get worse with the use of special Unicode characters like U+2100 (℀), or U+2105 (℅) which could lead the payload size to be tripled. Versions prior to 2.1.11 are affected by this vulnerability. The patch is included in 2.1.11.
CVSS Score
5.3
EPSS Score
0.009
Published
2024-09-10
An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to a use after free.
CVSS Score
7.8
EPSS Score
0.002
Published
2024-09-10
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
CVSS Score
9.8
EPSS Score
0.098
Published
2024-09-10
Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-09-10
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
CVSS Score
8.8
EPSS Score
0.003
Published
2024-09-10


Contact Us

Shodan ® - All rights reserved