Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

David Utón

#19155of 53,635
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2024-4649
6.2
2024-05-13
Moodle · Moodle · CVE-2024-33996
Name of the Vulnerable Software and Affected Versions: Moodle (affected versions not specified) Description: The issue is related to insufficient input validation, which could allow a remote attacker to execute arbitrary commands. It also involves incorrect validation of allowed event types in a calendar web service, enabling some users to create events with types or audiences they are not authorized to publish to. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-18174
7.8
2024-03-14
Sagemcom · Sagemcom Fast3686 V2 · CVE-2024-1623
**Name of the Vulnerable Software and Affected Versions** Sagemcom FAST3686 V2 Vodafone router (affected versions not specified) **Description** The issue is related to an insufficient session timeout in the Sagemcom FAST3686 V2 Vodafone router. This could allow a local attacker to access the administration panel without requiring login credentials. The vulnerability is possible because the 'Login.asp' and 'logout.asp' files do not handle session details correctly. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.