cbcvebase.

Trcore Dvc vulnerabilities

8 known vulnerabilities affecting trcore/dvc.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2024-11315P2CRITICALCVSS 9.8≥ 6.0, < 6.4≥ 6.0, ≤ 6.32024-11-18
CVE-2024-11315 [CRITICAL] CWE-23 CVE-2024-11315: The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded f The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
nvd
CVE-2024-11313P2CRITICALCVSS 9.8≥ 6.0, < 6.4≥ 6.0, ≤ 6.32024-11-18
CVE-2024-11313 [CRITICAL] CWE-23 CVE-2024-11313: The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded f The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
nvd
CVE-2024-11312P2CRITICALCVSS 9.8≥ 6.0, < 6.4≥ 6.0, ≤ 6.32024-11-18
CVE-2024-11312 [CRITICAL] CWE-23 CVE-2024-11312: The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded f The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
nvd
CVE-2024-11311P2CRITICALCVSS 9.8≥ 6.0, < 6.4≥ 6.0, ≤ 6.32024-11-18
CVE-2024-11311 [CRITICAL] CWE-23 CVE-2024-11311: The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded f The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
nvd
CVE-2024-11314P2CRITICALCVSS 9.8≥ 6.0, < 6.4≥ 6.0, ≤ 6.32024-11-18
CVE-2024-11314 [CRITICAL] CWE-23 CVE-2024-11314: The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded f The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
nvd
CVE-2024-11310P3HIGHCVSS 7.5≥ 6.0, < 6.4≥ 6.0, ≤ 6.32024-11-18
CVE-2024-11310 [HIGH] CWE-23 CVE-2024-11310: The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
nvd
CVE-2024-11309P3HIGHCVSS 7.5≥ 6.0, < 6.4≥ 6.0, ≤ 6.32024-11-18
CVE-2024-11309 [HIGH] CWE-23 CVE-2024-11309: The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
nvd
CVE-2024-11308P4MEDIUMCVSS 5.5≥ 6.0, < 6.4≥ 6.0, ≤ 6.32024-11-18
CVE-2024-11308 [MEDIUM] CWE-321 CVE-2024-11308: The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.
nvd
Trcore Dvc vulnerabilities | cvebase