#ExploitObserverAlert
ZDI-24-119
DESCRIPTION: Exploit Observer has 3 entries in 2 file formats related to ZDI-24-119. X.Org Server DisableDevice Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-21886.
ZDI-24-119
DESCRIPTION: Exploit Observer has 3 entries in 2 file formats related to ZDI-24-119. X.Org Server DisableDevice Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-21886.
#ExploitObserverAlert
PSS-177060
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177060. Red Hat Security Advisory 2024-0755-03. Red Hat Security Advisory 2024-0755-03 - An update for runc is now available for Red Hat Enterprise Linux 9.2 Extended Update Support.
PSS-177060
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177060. Red Hat Security Advisory 2024-0755-03. Red Hat Security Advisory 2024-0755-03 - An update for runc is now available for Red Hat Enterprise Linux 9.2 Extended Update Support.
#ExploitObserverAlert
CVE-2024-24815
DESCRIPTION: Exploit Observer has 4 entries in 2 file formats related to CVE-2024-24815. CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.
FIRST-EPSS: 0.000480000
CVE-2024-24815
DESCRIPTION: Exploit Observer has 4 entries in 2 file formats related to CVE-2024-24815. CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.
FIRST-EPSS: 0.000480000
#ExploitObserverAlert
PSS-177058
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177058. Ubuntu Security Notice USN-6627-1. Ubuntu Security Notice 6627-1 - It was discovered that libde265 could be made to read out of bounds. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. It was discovered that libde265 did not properly manage memory. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS.
PSS-177058
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177058. Ubuntu Security Notice USN-6627-1. Ubuntu Security Notice 6627-1 - It was discovered that libde265 could be made to read out of bounds. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. It was discovered that libde265 did not properly manage memory. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS.
#ExploitObserverAlert
PSS-177072
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177072. Gentoo Linux Security Advisory 202402-11. Gentoo Linux Security Advisory 202402-11 - Multiple denial of service vulnerabilities have been found in libxml2. Versions greater than or equal to 2.12.5 are affected.
PSS-177072
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177072. Gentoo Linux Security Advisory 202402-11. Gentoo Linux Security Advisory 202402-11 - Multiple denial of service vulnerabilities have been found in libxml2. Versions greater than or equal to 2.12.5 are affected.
#ExploitObserverAlert
WLB-2024020035
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to WLB-2024020035. Laravel Env file Access Open Directory.
WLB-2024020035
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to WLB-2024020035. Laravel Env file Access Open Directory.
#ExploitObserverAlert
EDB-51791
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51791. Online Nurse Hiring System 1.0 - Time-Based SQL Injection
EDB-51791
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to EDB-51791. Online Nurse Hiring System 1.0 - Time-Based SQL Injection
#ExploitObserverAlert
PSS-177065
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177065. Red Hat Security Advisory 2024-0759-03. Red Hat Security Advisory 2024-0759-03 - An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.8 Extended Update Support.
PSS-177065
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177065. Red Hat Security Advisory 2024-0759-03. Red Hat Security Advisory 2024-0759-03 - An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.8 Extended Update Support.
#ExploitObserverAlert
ZDI-24-101
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to ZDI-24-101. Allegra unzipFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2024-22513.
ZDI-24-101
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to ZDI-24-101. Allegra unzipFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2024-22513.
#ExploitObserverAlert
ZDI-24-111
DESCRIPTION: Exploit Observer has 5 entries in 2 file formats related to ZDI-24-111. Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-22360.
ZDI-24-111
DESCRIPTION: Exploit Observer has 5 entries in 2 file formats related to ZDI-24-111. Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-22360.
#ExploitObserverAlert
PSS-177048
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177048. Red Hat Security Advisory 2024-0728-03. Red Hat Security Advisory 2024-0728-03 - Logging Subsystem 5.8.3 - Red Hat OpenShift. Issues addressed include a denial of service vulnerability.
PSS-177048
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177048. Red Hat Security Advisory 2024-0728-03. Red Hat Security Advisory 2024-0728-03 - Logging Subsystem 5.8.3 - Red Hat OpenShift. Issues addressed include a denial of service vulnerability.
#ExploitObserverAlert
ZDI-24-100
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to ZDI-24-100. Allegra serveMathJaxLibraries Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-22532.
ZDI-24-100
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to ZDI-24-100. Allegra serveMathJaxLibraries Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-22532.
#ExploitObserverAlert
ZDI-24-110
DESCRIPTION: Exploit Observer has 8 entries in 2 file formats related to ZDI-24-110. Allegra downloadExportedChart Directory Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-22361.
ZDI-24-110
DESCRIPTION: Exploit Observer has 8 entries in 2 file formats related to ZDI-24-110. Allegra downloadExportedChart Directory Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-22361.
#ExploitObserverAlert
PSS-177067
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177067. Red Hat Security Advisory 2024-0764-03. Red Hat Security Advisory 2024-0764-03 - An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.6 Extended Update Support.
PSS-177067
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177067. Red Hat Security Advisory 2024-0764-03. Red Hat Security Advisory 2024-0764-03 - An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.6 Extended Update Support.
#ExploitObserverAlert
PSS-177056
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177056. Red Hat Security Advisory 2024-0752-03. Red Hat Security Advisory 2024-0752-03 - An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.
PSS-177056
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177056. Red Hat Security Advisory 2024-0752-03. Red Hat Security Advisory 2024-0752-03 - An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.
#ExploitObserverAlert
PSS-177066
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177066. Red Hat Security Advisory 2024-0760-03. Red Hat Security Advisory 2024-0760-03 - An update for the container-tools:3.0 module is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.
PSS-177066
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177066. Red Hat Security Advisory 2024-0760-03. Red Hat Security Advisory 2024-0760-03 - An update for the container-tools:3.0 module is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.
#ExploitObserverAlert
CVE-2024-25109
DESCRIPTION: Exploit Observer has 2 entries in 2 file formats related to CVE-2024-25109. ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the `columns` and `help` keys on the form descriptor. An attacker may exploit this and would have a cross site scripting attack vector. Exploiting this on-wiki requires the `(editinterface)` right. Users should apply the code changes in commits `886cc6b94`, `2ef0f50880`, and `6942e8b2c` to resolve this vulnerability. There are no known workarounds for this vulnerability.
FIRST-EPSS: 0.000450000
CVE-2024-25109
DESCRIPTION: Exploit Observer has 2 entries in 2 file formats related to CVE-2024-25109. ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the `columns` and `help` keys on the form descriptor. An attacker may exploit this and would have a cross site scripting attack vector. Exploiting this on-wiki requires the `(editinterface)` right. Users should apply the code changes in commits `886cc6b94`, `2ef0f50880`, and `6942e8b2c` to resolve this vulnerability. There are no known workarounds for this vulnerability.
FIRST-EPSS: 0.000450000
#ExploitObserverAlert
ZDI-24-099
DESCRIPTION: Exploit Observer has 2 entries in 2 file formats related to ZDI-24-099. Allegra getFileContentAsString Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Although authentication is required to exploit this vulnerability, the product implements a registration mechanism that can be used to create a new user with a sufficient privilege level. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-22530.
ZDI-24-099
DESCRIPTION: Exploit Observer has 2 entries in 2 file formats related to ZDI-24-099. Allegra getFileContentAsString Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Although authentication is required to exploit this vulnerability, the product implements a registration mechanism that can be used to create a new user with a sufficient privilege level. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-22530.
#ExploitObserverAlert
PSS-177071
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177071. Debian Security Advisory 5618-1. Debian Linux Security Advisory 5618-1 - Vulnerabilities have been discovered in the WebKitGTK web engine. An anonymous researcher discovered that a maliciously crafted webpage may be able to fingerprint the user. Wangtaiyu discovered that processing web content may lead to arbitrary code execution. Apple discovered that processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
PSS-177071
DESCRIPTION: Exploit Observer has 1 entries in 1 file formats related to PSS-177071. Debian Security Advisory 5618-1. Debian Linux Security Advisory 5618-1 - Vulnerabilities have been discovered in the WebKitGTK web engine. An anonymous researcher discovered that a maliciously crafted webpage may be able to fingerprint the user. Wangtaiyu discovered that processing web content may lead to arbitrary code execution. Apple discovered that processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
#ExploitObserverAlert
CVE-2024-24820
DESCRIPTION: Exploit Observer has 6 entries in 2 file formats related to CVE-2024-24820. Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attackers to perform changes in the monitoring environment managed by Icinga Director without the awareness of the victim. Users of the map module in version 1.x, should immediately upgrade to v2.0. The mentioned XSS vulnerabilities in Icinga Web are already fixed as well and upgrades to the most recent release of the 2.9, 2.10 or 2.11 branch must be performed if not done yet. Any later major release is also suitable. Icinga Director will receive minor updates to the 1.8, 1.9, 1.10 and 1.11 branches to remedy this issue. Upgrade immediately to a patched release. If that is not feasible, disable the director module for the time being.
FIRST-EPSS: 0.000440000
CVE-2024-24820
DESCRIPTION: Exploit Observer has 6 entries in 2 file formats related to CVE-2024-24820. Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attackers to perform changes in the monitoring environment managed by Icinga Director without the awareness of the victim. Users of the map module in version 1.x, should immediately upgrade to v2.0. The mentioned XSS vulnerabilities in Icinga Web are already fixed as well and upgrades to the most recent release of the 2.9, 2.10 or 2.11 branch must be performed if not done yet. Any later major release is also suitable. Icinga Director will receive minor updates to the 1.8, 1.9, 1.10 and 1.11 branches to remedy this issue. Upgrade immediately to a patched release. If that is not feasible, disable the director module for the time being.
FIRST-EPSS: 0.000440000
#ExploitObserverAlert
CVE-2024-22836
DESCRIPTION: Exploit Observer has 2 entries in 2 file formats related to CVE-2024-22836. An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
FIRST-EPSS: 0.000450000
CVE-2024-22836
DESCRIPTION: Exploit Observer has 2 entries in 2 file formats related to CVE-2024-22836. An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
FIRST-EPSS: 0.000450000