|
312201
|
6.5 |
MEDIUM
Network
|
microsoft
|
outlook
|
Microsoft Outlook for iOS Information Disclosure Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43482
|
2024-09-18 23:11 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312202
|
6.5 |
MEDIUM
Network
|
microsoft
|
windows_server_2012 windows_10_1507 windows_10_1809 windows_server_2019 windows_10_21h2 windows_10_1607 windows_server_2016 windows_10_22h2
|
Windows Mark of the Web Security Feature Bypass Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43487
|
2024-09-18 23:10 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312203
|
7.8 |
HIGH
Local
|
microsoft
|
autoupdate
|
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43492
|
2024-09-18 22:57 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312204
|
7.3 |
HIGH
Local
|
microsoft
|
windows_11_22h2 windows_server_2022_23h2 windows_11_23h2
|
Windows libarchive Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43495
|
2024-09-18 22:55 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312205
|
7.8 |
HIGH
Local
|
google
|
android
|
there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
|
NVD-CWE-noinfo
|
CVE-2024-29779
|
2024-09-18 22:52 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312206
|
7.8 |
HIGH
Local
|
google
|
android
|
In TBD of TBD, there is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege with no additional executio…
|
NVD-CWE-noinfo
|
CVE-2024-44092
|
2024-09-18 22:51 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312207
|
7.8 |
HIGH
Local
|
google
|
android
|
In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privi…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44093
|
2024-09-18 22:42 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312208
|
7.8 |
HIGH
Local
|
google
|
android
|
In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privi…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44094
|
2024-09-18 22:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312209
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of s…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2024-2800
|
2024-09-18 21:42 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312210
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When view…
|
CWE-79
Cross-site Scripting
|
CVE-2024-4207
|
2024-09-18 21:41 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312211
|
8.8 |
HIGH
Network
|
google microsoft
|
chrome edge_chromium
|
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7965
|
2024-09-18 21:40 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312212
|
8.8 |
HIGH
Network
|
redhat
|
openshift_data_science openshift_ai
|
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option …
|
NVD-CWE-Other
|
CVE-2024-7557
|
2024-09-18 16:15 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312213
|
6.7 |
MEDIUM
Local
|
microsoft
|
windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_server_2022_…
|
Summary:
Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machin…
|
NVD-CWE-Other
|
CVE-2024-21302
|
2024-09-18 09:15 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312214
|
7.5 |
HIGH
Network
|
containers
|
aardvark-dns
|
A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open…
|
NVD-CWE-noinfo
|
CVE-2024-8418
|
2024-09-18 05:15 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312215
|
4.3 |
MEDIUM
Network
|
imagerecycle
|
imagerecycle_pdf_\&_image_compression
|
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce valid…
|
CWE-352
Origin Validation Error
|
CVE-2024-8120
|
2024-09-18 05:07 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312216
|
4.8 |
MEDIUM
Network
|
cleversoft
|
clever_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CleverSoft Clever Addons for Elementor allows Stored XSS.This issue affects Clever Addons …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43324
|
2024-09-18 05:04 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312217
|
6.1 |
MEDIUM
Network
|
orbisius
|
child_theme_creator
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Child Theme Creator allows Reflected XSS.This issue affects Chil…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43276
|
2024-09-18 05:00 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312218
|
5.4 |
MEDIUM
Network
|
cpothemes
|
allegiant
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Chill Allegiant allegiant allows Stored XSS.This issue affects Allegiant: from n/a thro…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43329
|
2024-09-18 04:59 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312219
|
6.1 |
MEDIUM
Network
|
wpbeaveraddons
|
powerpack_lite_for_beaver_builder
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack for Beaver Builder allows Reflected XSS.This issue affects Pow…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43330
|
2024-09-18 04:53 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312220
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ES…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-7526
|
2024-09-18 04:15 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312221
|
5.4 |
MEDIUM
Network
|
mayurik
|
best_house_rental_management_system
|
A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /index.php?page=tenants of the componen…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8610
|
2024-09-18 03:48 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312222
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-x4860_firmware
|
The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execu…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-45695
|
2024-09-18 03:40 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312223
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-x5460_firmware dir-x4860_firmware
|
The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execu…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2024-45694
|
2024-09-18 03:40 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312224
|
- |
-
|
-
|
-
|
Rejected reason: This CVE is a duplicate of another CVE.
|
-
|
CVE-2024-45804
|
2024-09-18 03:15 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312225
|
6.5 |
MEDIUM
Network
|
bitapps
|
bit_form
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit Form Pro: from n/a through 2.6.4.
|
NVD-CWE-noinfo
|
CVE-2024-43251
|
2024-09-18 03:10 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312226
|
9.6 |
CRITICAL
Network
|
joplin_project
|
joplin
|
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to d…
|
CWE-79
Cross-site Scripting
|
CVE-2024-40643
|
2024-09-18 03:03 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312227
|
6.5 |
MEDIUM
Network
|
techexcel
|
back_office_software
|
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulne…
|
CWE-863
Incorrect Authorization
|
CVE-2024-8601
|
2024-09-18 02:54 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312228
|
7.1 |
HIGH
Local
|
microsoft
|
azure_network_watcher_agent
|
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38188
|
2024-09-18 02:49 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312229
|
7.3 |
HIGH
Local
|
microsoft
|
azure_network_watcher_agent
|
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43470
|
2024-09-18 02:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312230
|
3.1 |
LOW
Adjacent
|
rapid7
|
insight_platform
|
Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of…
|
CWE-862
Missing Authorization
|
CVE-2024-8042
|
2024-09-18 02:25 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312231
|
7.5 |
HIGH
Adjacent
|
microsoft
|
windows_10_1507 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_11_24h2 windows_10_1607 windows_server_2016 windows_10_22h2 windows_11_23h2 windows…
|
Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38119
|
2024-09-18 02:23 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312232
|
9.9 |
CRITICAL
Network
|
microsoft
|
azure_web_apps
|
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.
|
NVD-CWE-noinfo
|
CVE-2024-38194
|
2024-09-18 02:02 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312233
|
9.0 |
CRITICAL
Network
|
microsoft
|
azure_stack_hub
|
Azure Stack Hub Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38216
|
2024-09-18 02:00 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312234
|
7.5 |
HIGH
Network
|
dlink
|
di-8100_firmware
|
D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44375
|
2024-09-18 02:00 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312235
|
9.0 |
CRITICAL
Network
|
microsoft
|
azure_stack_hub
|
Azure Stack Hub Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38220
|
2024-09-18 01:59 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312236
|
9.8 |
CRITICAL
Network
|
microsoft
|
dynamics_365_business_central
|
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38225
|
2024-09-18 01:58 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312237
|
7.2 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Microsoft SharePoint Server Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38228
|
2024-09-18 01:57 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312238
|
7.2 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Microsoft SharePoint Server Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38227
|
2024-09-18 01:57 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312239
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2012 windows_server_2019 windows_server_2022 windows_server_2016
|
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38230
|
2024-09-18 01:56 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312240
|
7.2 |
HIGH
Network
|
qnap
|
qts quts_hero
|
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands …
|
CWE-78
OS Command
|
CVE-2023-34979
|
2024-09-18 01:54 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312241
|
7.5 |
HIGH
Network
|
microsoft
|
windows_10_1607 windows_server_2016
|
Windows Networking Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38232
|
2024-09-18 01:52 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312242
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_server_2016
|
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38231
|
2024-09-18 01:52 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312243
|
7.5 |
HIGH
Network
|
microsoft
|
windows_10_1607 windows_server_2016
|
Windows Networking Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38233
|
2024-09-18 01:51 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312244
|
6.5 |
MEDIUM
Adjacent
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_serv…
|
Windows Networking Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38234
|
2024-09-18 01:50 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312245
|
6.5 |
MEDIUM
Local
|
microsoft
|
windows_10_1507 windows_server_2019 windows_server_2022 windows_11_21h2 windows_11_22h2 windows_server_2022_23h2 windows_11_24h2 windows_10_1607 windows_server_2016 windows…
|
Windows Hyper-V Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38235
|
2024-09-18 01:43 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312246
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_server_2016
|
DHCP Server Service Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38236
|
2024-09-18 01:42 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312247
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_server_2022_23h2 windows_11_24h2 windows_10_…
|
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38237
|
2024-09-18 01:41 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312248
|
7.2 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_serv…
|
Windows Kerberos Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38239
|
2024-09-18 01:40 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312249
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_server_2022_23h2 windows_11_24h2 windows_10_…
|
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38238
|
2024-09-18 01:40 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312250
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_server_2012 windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_server_2022_23h2 windows…
|
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38240
|
2024-09-18 01:38 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|