Vulnerabilities
30 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-42642 | Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from th Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page. NVD description · AI analysis pending | 6.7 | <1% | PoC |
| — | |
| CVE-2024-45169 | An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution via the \xB0\x00\x3c byte sequence. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2024-2724 | SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2024-25711 | diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-49339 | Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint. Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2023-3620 | Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1. Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1. NVD description · AI analysis pending | 5.4 | <1% | PoC ×2 |
| — | |
| CVE-2023-3071 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-2822 | A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.10.6 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-229596. NVD description · AI analysis pending | 6.1 | 3% | PoC ×2 |
| — | |
| CVE-2022-33155 | The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows XSS. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2021-36887 +1 in the same advisory: …36889 | Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plug Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass". NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2019-8978 | An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner En An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session (and cause a denial of service) by repeatedly requesting the initial Banner Web Tailor main page with the IDMSESSID cookie set to the victim's UDCID, which in the case tested is the institutional ID. During a login attempt by a victim, the attacker can leverage the race condition and will be issued the SESSID that was meant for this victim. NVD description · AI analysis pending | 8.1 | 6% |
| — | ||
| CVE-2017-16122 | cuciuci is a simple fileserver. cuciuci is a simple fileserver. cuciuci is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2017-0359 | diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive. diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2017-7402 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request f Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg. NVD description · AI analysis pending | 9.8 | 5% | PoC |
| — | |
| CVE-2017-7359 | Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — |