CVE-2024-38644
- EPSS 1.15%
- Veröffentlicht 22.11.2024 16:15:25
- Zuletzt bearbeitet 20.09.2025 03:31:49
An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Note...
CVE-2024-38645
- EPSS 0.11%
- Veröffentlicht 22.11.2024 16:15:25
- Zuletzt bearbeitet 20.09.2025 03:31:19
A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the follo...
- EPSS 0.02%
- Veröffentlicht 22.11.2024 16:15:25
- Zuletzt bearbeitet 20.09.2025 03:29:56
An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the r...
CVE-2024-38643
- EPSS 0.44%
- Veröffentlicht 22.11.2024 16:15:24
- Zuletzt bearbeitet 20.09.2025 03:32:31
A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnera...
CVE-2024-27126
- EPSS 0.65%
- Veröffentlicht 06.09.2024 17:15:15
- Zuletzt bearbeitet 20.12.2024 15:49:05
A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following ...
CVE-2024-27122
- EPSS 0.65%
- Veröffentlicht 06.09.2024 17:15:14
- Zuletzt bearbeitet 20.12.2024 15:48:58
A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following ...