|
312151
|
- |
-
|
-
|
-
|
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the cont…
|
CWE-200
Information Exposure
|
CVE-2024-42351
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312152
|
- |
-
|
-
|
-
|
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations en…
|
CWE-79
Cross-site Scripting
|
CVE-2024-42346
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312153
|
- |
-
|
-
|
-
|
Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.
|
-
|
CVE-2024-42697
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312154
|
- |
-
|
-
|
-
|
The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. Howeve…
|
-
|
CVE-2024-45229
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312155
|
- |
-
|
-
|
-
|
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to cr…
|
-
|
CVE-2024-45489
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312156
|
- |
-
|
-
|
-
|
A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument tid leads to …
|
CWE-89
SQL Injection
|
CVE-2024-9037
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312157
|
- |
-
|
-
|
-
|
A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. The manipulation of the argument i…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-9036
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312158
|
- |
-
|
-
|
-
|
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.
|
-
|
CVE-2024-46652
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312159
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/login.php of the component Admin Login…
|
CWE-89
SQL Injection
|
CVE-2024-9035
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312160
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulatio…
|
CWE-89
SQL Injection
|
CVE-2024-9034
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312161
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Check index for aux_rd_interval before using
aux_rd_interval has size of 7 and should be checked.
This fixes 3 …
|
NVD-CWE-noinfo
|
CVE-2024-46728
|
2024-09-26 22:31 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312162
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/pm: fix the Out-of-bounds read warning
using index i - 1U may beyond element index
for mc_data[] when i = 0.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-46731
|
2024-09-26 22:29 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312163
|
5.4 |
MEDIUM
Network
|
puma
|
puma
|
Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing a underscore version of the …
|
CWE-444
HTTP Request Smuggling
|
CVE-2024-45614
|
2024-09-26 22:28 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312164
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Assign linear_pitch_alignment even for VM
[Description]
Assign linear_pitch_alignment so we don't cause a divide…
|
CWE-369
Divide By Zero
|
CVE-2024-46732
|
2024-09-26 22:28 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312165
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
mwifiex_get_priv_by_id() returns the priv pointer correspond…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46755
|
2024-09-26 22:25 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312166
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ice: protect XDP configuration with a mutex
The main threat to data consistency in ice_xdp() is a possible asynchronous
PF reset.…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46765
|
2024-09-26 22:24 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312167
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup
Currently napi_disable() gets called during rxq and txq clean…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-46784
|
2024-09-26 22:21 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312168
|
- |
-
|
-
|
-
|
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived chan…
|
-
|
CVE-2024-47145
|
2024-09-26 17:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312169
|
- |
-
|
-
|
-
|
Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a pe…
|
-
|
CVE-2024-47003
|
2024-09-26 17:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312170
|
- |
-
|
-
|
-
|
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deploy…
|
-
|
CVE-2024-45843
|
2024-09-26 17:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312171
|
- |
-
|
-
|
-
|
User interface (UI) misrepresentation of critical information issue exists in multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION. If this vulnerabi…
|
-
|
CVE-2024-47045
|
2024-09-26 13:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312172
|
- |
-
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-22303
|
2024-09-26 12:15 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312173
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_10_1507
|
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released Ju…
|
NVD-CWE-noinfo
|
CVE-2024-43491
|
2024-09-26 10:00 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312174
|
- |
-
|
-
|
-
|
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: It is a duplicate of CVE-2010-2799.
|
-
|
CVE-2010-10005
|
2024-09-26 08:15 |
2023-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312175
|
- |
-
|
-
|
-
|
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafte…
|
-
|
CVE-2024-41433
|
2024-09-26 06:15 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312176
|
- |
-
|
-
|
-
|
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnne…
|
-
|
CVE-2024-41434
|
2024-09-26 06:15 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312177
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortianalyzer fortimanager fortianalyzer-bigdata
|
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2023-44254
|
2024-09-26 05:17 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312178
|
5.4 |
MEDIUM
Network
|
sktthemes
|
posterity
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sonalsinha21 Posterity allows Stored XSS.This issue affects Posterity: from n/a through 3.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43995
|
2024-09-26 05:01 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312179
|
8.8 |
HIGH
Network
|
microsoft
|
groupme
|
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.
|
NVD-CWE-noinfo
|
CVE-2024-38183
|
2024-09-26 04:59 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312180
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a …
|
CWE-601
Open Redirect
|
CVE-2024-8897
|
2024-09-26 04:49 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312181
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15. Privacy Indicators for microphone or camera access may be attributed incorrectly.
|
NVD-CWE-noinfo
|
CVE-2024-27875
|
2024-09-26 04:44 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312182
|
4.6 |
MEDIUM
Physics
|
apple
|
iphone_os ipados
|
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data.
|
NVD-CWE-noinfo
|
CVE-2024-40840
|
2024-09-26 04:42 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312183
|
8.8 |
HIGH
Network
|
pickplugins
|
post_grid
|
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta value…
|
NVD-CWE-noinfo
|
CVE-2024-8253
|
2024-09-26 04:42 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312184
|
4.8 |
MEDIUM
Network
|
enviragallery
|
envira_gallery
|
The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform…
|
CWE-79
Cross-site Scripting
|
CVE-2024-3899
|
2024-09-26 04:37 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312185
|
4.8 |
MEDIUM
Network
|
gsplugins
|
gs_logo_slider
|
The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks e…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7716
|
2024-09-26 04:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312186
|
5.4 |
MEDIUM
Network
|
wpdeveloper
|
essential_addons_for_elementor
|
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widge…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8440
|
2024-09-26 04:34 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312187
|
8.1 |
HIGH
Network
|
wpdelicious
|
wp_delicious
|
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to insufficient file path validation in t…
|
NVD-CWE-Other
|
CVE-2024-7626
|
2024-09-26 04:32 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312188
|
8.8 |
HIGH
Network
|
fairsketch
|
rise_ultimate_project_manager
|
A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboard/save. The manipul…
|
CWE-89
SQL Injection
|
CVE-2024-8945
|
2024-09-26 04:24 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312189
|
4.3 |
MEDIUM
Network
|
contao
|
contao
|
Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13…
|
CWE-22
Path Traversal
|
CVE-2024-45604
|
2024-09-26 04:22 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312190
|
5.4 |
MEDIUM
Network
|
wpbackgrounds
|
advanced_wordpress_backgrounds
|
The Advanced WordPress Backgrounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘imageTag’ parameter in all versions up to, and including, 1.12.3 due to insufficient inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8045
|
2024-09-26 04:22 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312191
|
8.8 |
HIGH
Network
|
contao
|
contao
|
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.1…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-45398
|
2024-09-26 04:20 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312192
|
4.8 |
MEDIUM
Network
|
eladmin
|
eladmin
|
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44676
|
2024-09-26 04:20 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312193
|
9.8 |
CRITICAL
Network
|
eladmin
|
eladmin
|
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-44677
|
2024-09-26 04:19 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312194
|
8.8 |
HIGH
Network
|
microsoft
|
dynamics_365_business_central
|
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
|
NVD-CWE-noinfo
|
CVE-2024-43460
|
2024-09-26 04:18 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312195
|
4.6 |
MEDIUM
Physics
|
hathway
|
skyworth_cm5100-511_firmware
|
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-44815
|
2024-09-26 04:17 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312196
|
8.8 |
HIGH
Network
|
hfo4
|
shudong-share
|
A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /includes/fileReceive.php of the compon…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8338
|
2024-09-26 04:12 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312197
|
5.3 |
MEDIUM
Network
|
getastra
|
wp_hardening
|
The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular ex…
|
CWE-697
Incorrect Comparison
|
CVE-2024-6641
|
2024-09-26 04:07 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312198
|
6.1 |
MEDIUM
Network
|
svelte
|
svelte
|
svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The as…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45047
|
2024-09-26 04:06 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312199
|
6.1 |
MEDIUM
Network
|
elizsoftware
|
panel
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.
|
CWE-79
Cross-site Scripting
|
CVE-2024-6877
|
2024-09-26 03:57 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312200
|
9.8 |
CRITICAL
Network
|
elizsoftware
|
panel
|
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.
|
CWE-256
Plaintext Storage of a Password
|
CVE-2024-5960
|
2024-09-26 03:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|