|
312101
|
- |
-
|
-
|
-
|
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.
|
-
|
CVE-2023-26686
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312102
|
- |
-
|
-
|
-
|
The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, an…
|
-
|
CVE-2022-2439
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312103
|
4.9 |
MEDIUM
Network
|
-
|
-
|
An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2024-38266
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312104
|
- |
-
|
-
|
-
|
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
|
-
|
CVE-2024-7024
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312105
|
- |
-
|
-
|
-
|
Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
|
-
|
CVE-2024-7023
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312106
|
- |
-
|
-
|
-
|
Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
|
-
|
CVE-2024-7022
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312107
|
- |
-
|
-
|
-
|
Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
|
-
|
CVE-2024-7020
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312108
|
- |
-
|
-
|
-
|
Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML p…
|
-
|
CVE-2024-7019
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312109
|
- |
-
|
-
|
-
|
Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
|
-
|
CVE-2024-7018
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312110
|
- |
-
|
-
|
-
|
Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a cr…
|
-
|
CVE-2023-7282
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312111
|
- |
-
|
-
|
-
|
Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
|
-
|
CVE-2023-7281
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312112
|
- |
-
|
-
|
-
|
Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2021-38023
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312113
|
- |
-
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields messa…
|
-
|
CVE-2024-46639
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312114
|
- |
-
|
-
|
-
|
Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.
|
-
|
CVE-2024-44540
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312115
|
- |
-
|
-
|
-
|
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.
|
-
|
CVE-2024-39843
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312116
|
- |
-
|
-
|
-
|
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.
|
-
|
CVE-2024-39842
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312117
|
- |
-
|
-
|
-
|
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process th…
|
-
|
CVE-2024-39342
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312118
|
- |
-
|
-
|
-
|
A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.js…
|
-
|
CVE-2023-46948
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312119
|
- |
-
|
-
|
-
|
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthor…
|
-
|
CVE-2024-9014
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312120
|
- |
-
|
-
|
-
|
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote att…
|
-
|
CVE-2024-40442
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312121
|
- |
-
|
-
|
-
|
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote att…
|
-
|
CVE-2024-40441
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312122
|
- |
-
|
-
|
-
|
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.
|
-
|
CVE-2024-41228
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312123
|
- |
-
|
-
|
-
|
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.
|
-
|
CVE-2024-34331
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312124
|
- |
-
|
-
|
-
|
Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony…
|
-
|
CVE-2024-23934
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312125
|
- |
-
|
-
|
-
|
Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations…
|
-
|
CVE-2024-23933
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312126
|
- |
-
|
-
|
-
|
PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.
|
-
|
CVE-2024-46241
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312127
|
- |
-
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Informatics Software Ferry Reservation System allows Reflected XSS.This issue affect…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7835
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312128
|
- |
-
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Exnet Informatics Software Ferry Reservation System allows SQL Injection.This issue affects Ferry…
|
CWE-89
SQL Injection
|
CVE-2024-7735
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312129
|
- |
-
|
-
|
-
|
Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38…
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2024-8903
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312130
|
- |
-
|
-
|
-
|
YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbi…
|
-
|
CVE-2024-7846
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312131
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
media: vivid: fix compose size exceed boundary
syzkaller found a bug:
BUG: unable to handle page fault for address: ffffc9000a3…
|
-
|
CVE-2022-48945
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312132
|
- |
-
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inclusion.This issue affects ElementsKit Pro: from n/…
|
CWE-22
Path Traversal
|
CVE-2024-43996
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312133
|
- |
-
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated use…
|
-
|
CVE-2024-47226
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312134
|
- |
-
|
-
|
-
|
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTT…
|
-
|
CVE-2024-47220
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312135
|
- |
-
|
-
|
-
|
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
|
-
|
CVE-2024-47219
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312136
|
- |
-
|
-
|
-
|
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.
|
-
|
CVE-2024-47218
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312137
|
- |
-
|
-
|
-
|
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
|
-
|
CVE-2024-47210
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312138
|
- |
-
|
-
|
-
|
eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
|
-
|
CVE-2024-46649
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312139
|
- |
-
|
-
|
-
|
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.
|
-
|
CVE-2024-46648
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312140
|
- |
-
|
-
|
-
|
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
|
-
|
CVE-2024-46647
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312141
|
- |
-
|
-
|
-
|
eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.
|
-
|
CVE-2024-46646
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312142
|
- |
-
|
-
|
-
|
eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
|
-
|
CVE-2024-46645
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312143
|
- |
-
|
-
|
-
|
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.
|
-
|
CVE-2024-46644
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312144
|
- |
-
|
-
|
-
|
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote…
|
-
|
CVE-2024-46640
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312145
|
- |
-
|
-
|
-
|
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
|
-
|
CVE-2024-46103
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312146
|
- |
-
|
-
|
-
|
GDidees CMS <= v3.9.1 has a file upload vulnerability.
|
-
|
CVE-2024-46101
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312147
|
- |
-
|
-
|
-
|
Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site scripting vulnerability: GET /v1/cr…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45793
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312148
|
- |
-
|
-
|
-
|
Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding pa…
|
CWE-89
SQL Injection
|
CVE-2024-47062
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312149
|
- |
-
|
-
|
-
|
Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM att…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47061
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312150
|
- |
-
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
-
|
CVE-2024-46654
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|