|
311951
|
6.1 |
MEDIUM
Network
|
glpi-project
|
glpi
|
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.1…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43418
|
2024-11-21 00:20 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311952
|
9.8 |
CRITICAL
Network
|
trcore
|
dvc
|
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, lead…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11311
|
2024-11-21 00:17 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311953
|
7.5 |
HIGH
Network
|
trcore
|
dvc
|
The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
|
CWE-22
Path Traversal
|
CVE-2024-11310
|
2024-11-21 00:17 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311954
|
7.5 |
HIGH
Network
|
trcore
|
dvc
|
The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
|
CWE-22
Path Traversal
|
CVE-2024-11309
|
2024-11-21 00:17 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311955
|
5.5 |
MEDIUM
Local
|
trcore
|
dvc
|
The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.
|
NVD-CWE-Other
|
CVE-2024-11308
|
2024-11-21 00:17 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311956
|
9.8 |
CRITICAL
Network
|
trcore
|
dvc
|
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, lead…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11315
|
2024-11-21 00:16 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311957
|
9.8 |
CRITICAL
Network
|
trcore
|
dvc
|
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, lead…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11314
|
2024-11-21 00:16 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311958
|
9.8 |
CRITICAL
Network
|
trcore
|
dvc
|
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, lead…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11313
|
2024-11-21 00:16 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311959
|
9.8 |
CRITICAL
Network
|
trcore
|
dvc
|
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, lead…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11312
|
2024-11-21 00:16 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311960
|
6.1 |
MEDIUM
Network
|
ibphoenix
|
ibwebadmin
|
A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /database.php of the component Banco de Dados Tab. …
|
CWE-79
Cross-site Scripting
|
CVE-2024-11240
|
2024-11-21 00:09 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311961
|
4.3 |
MEDIUM
Network
|
themify
|
builder
|
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This …
|
CWE-863
Incorrect Authorization
|
CVE-2024-7836
|
2024-11-21 00:09 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311962
|
9.6 |
CRITICAL
Network
|
github
|
cli
|
The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been …
|
CWE-77
Command Injection
|
CVE-2024-52308
|
2024-11-21 00:07 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311963
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary Jav…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49754
|
2024-11-21 00:02 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311964
|
6.1 |
MEDIUM
Network
|
cleancoder
|
fitnesse
|
Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-39610
|
2024-11-21 00:02 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311965
|
6.1 |
MEDIUM
Network
|
wpplugins
|
hide_my_wp_ghost
|
The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10825
|
2024-11-21 00:01 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311966
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
|
CWE-863
Incorrect Authorization
|
CVE-2024-48897
|
2024-11-20 23:48 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311967
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messagin…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-48896
|
2024-11-20 23:47 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311968
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
|
CWE-862
Missing Authorization
|
CVE-2024-48898
|
2024-11-20 23:46 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311969
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
|
CWE-863
Incorrect Authorization
|
CVE-2024-48901
|
2024-11-20 23:45 |
2024-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311970
|
9.8 |
CRITICAL
Network
|
really-simple-plugins
|
really_simple_security
|
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-10924
|
2024-11-20 23:44 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311971
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Custom OID" tab of a device allows authenticated users to inject …
|
CWE-79
Cross-site Scripting
|
CVE-2024-51497
|
2024-11-20 23:41 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311972
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51495
|
2024-11-20 23:41 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311973
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51494
|
2024-11-20 23:40 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311974
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Capture Debug Information" page allows authenticated users to inj…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49764
|
2024-11-20 23:40 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311975
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Manage User Access" page allows authenticated users to inject arb…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49759
|
2024-11-20 23:40 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311976
|
4.8 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can add Notes to a device, the application did not properly sanitize the user input, when the ExampleP…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49758
|
2024-11-20 23:40 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311977
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-52526
|
2024-11-20 23:39 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311978
|
4.8 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can edit the Display Name of a device, the application did not properly sanitize the user input in the…
|
CWE-79
Cross-site Scripting
|
CVE-2024-50355
|
2024-11-20 23:39 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311979
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2024-50350
|
2024-11-20 23:39 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311980
|
7.8 |
HIGH
Local
|
qualcomm
|
ar8035_firmware csra6620_firmware csra6640_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_platform…
|
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
|
CWE-416
Use After Free
|
CVE-2024-33028
|
2024-11-20 23:39 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311981
|
7.8 |
HIGH
Local
|
qualcomm
|
315_5g_iot_modem_firmware aqt1000_firmware ar8031_firmware c-v2x_9150_firmware csra6620_firmware csra6640_firmware fastconnect_6200_firmware qca6174a_firmware qca6310_firmware…
|
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
|
NVD-CWE-Other
|
CVE-2024-33027
|
2024-11-20 23:38 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311982
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticate…
|
CWE-79
Cross-site Scripting
|
CVE-2024-50352
|
2024-11-20 23:37 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311983
|
7.5 |
HIGH
Network
|
anisha
|
farmacia
|
A vulnerability, which was classified as critical, has been found in code-projects Farmacia 1.0. This issue affects some unknown processing of the file /editar-produto.php. The manipulation of the ar…
|
CWE-89
SQL Injection
|
CVE-2024-11245
|
2024-11-20 23:36 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311984
|
9.8 |
CRITICAL
Network
|
anisha
|
farmacia
|
A vulnerability classified as critical was found in code-projects Farmacia 1.0. This vulnerability affects unknown code of the file /editar-cliente.php. The manipulation of the argument id leads to s…
|
CWE-89
SQL Injection
|
CVE-2024-11244
|
2024-11-20 23:36 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311985
|
6.1 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability exis…
|
CWE-79
Cross-site Scripting
|
CVE-2024-20538
|
2024-11-20 23:36 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311986
|
7.5 |
HIGH
Network
|
ibm
|
sterling_secure_proxy
|
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request c…
|
CWE-22
Path Traversal
|
CVE-2024-41784
|
2024-11-20 23:35 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311987
|
5.4 |
MEDIUM
Network
|
anisha
|
farmacia
|
A vulnerability, which was classified as problematic, was found in code-projects Farmacia 1.0. Affected is an unknown function of the file /adicionar-cliente.php. The manipulation of the argument nom…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11246
|
2024-11-20 23:35 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311988
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-125
Out-of-bounds Read
|
CVE-2024-52567
|
2024-11-20 23:33 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311989
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-52566
|
2024-11-20 23:33 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311990
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-52565
|
2024-11-20 23:33 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311991
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-52573
|
2024-11-20 23:32 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311992
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-52572
|
2024-11-20 23:32 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311993
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-52571
|
2024-11-20 23:32 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311994
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-52570
|
2024-11-20 23:32 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311995
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-52569
|
2024-11-20 23:32 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311996
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-416
Use After Free
|
CVE-2024-52568
|
2024-11-20 23:32 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311997
|
7.8 |
HIGH
Local
|
siemens
|
tecnomatix_plant_simulation
|
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain …
|
CWE-125
Out-of-bounds Read
|
CVE-2024-52574
|
2024-11-20 23:31 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311998
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
kunit/overflow: Fix UB in overflow_allocation_test
The 'device_name' array doesn't exist out of the
'overflow_allocation_test' fu…
|
NVD-CWE-noinfo
|
CVE-2024-46823
|
2024-11-20 22:59 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311999
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: Avoid NULL dereference in msm_disp_state_print_regs()
If the allocation in msm_disp_state_dump_regs() failed then
`block…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50156
|
2024-11-20 22:58 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312000
|
7.8 |
HIGH
Local
|
qualcomm
|
fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_platform_firmware qam8255p_firmware qam8295p_firmware qam862…
|
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
|
CWE-416
Use After Free
|
CVE-2024-33034
|
2024-11-20 22:54 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|