|
312251
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_server_2022_23h2 windows_11_24h2 windows_10_…
|
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38242
|
2024-09-18 01:37 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312252
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_server_2022_23h2 windows_11_24h2 windows_10_…
|
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38241
|
2024-09-18 01:37 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312253
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_server_2022_23h2 windows_11_24h2 windows_10_…
|
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38243
|
2024-09-18 01:36 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312254
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_server_2022_23h2 windows_11_24h2 windows_10_…
|
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38244
|
2024-09-18 01:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312255
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_serv…
|
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38245
|
2024-09-18 01:34 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312256
|
7.0 |
HIGH
Local
|
microsoft
|
windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_server_2022_23h2 windows_11_24h2 windows_10_22h2 windows_11_23h2
|
Win32k Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38246
|
2024-09-18 01:33 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312257
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_serv…
|
Windows Graphics Component Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38247
|
2024-09-18 01:30 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312258
|
7.0 |
HIGH
Local
|
microsoft
|
windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_server_2022_23h2 windows_11_24h2 windows_10_22h2 windows_11_23h2
|
Windows Storage Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38248
|
2024-09-18 01:29 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312259
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_serv…
|
Windows Graphics Component Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38249
|
2024-09-18 01:28 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312260
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 office_long_term_servicing_channel office windows_10_1507 windows_10_1607 windows_server_2019 windows_server_2022 windows_server_2016
|
Windows Graphics Component Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38250
|
2024-09-18 01:27 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312261
|
7.8 |
HIGH
Local
|
microsoft
|
windows_11_24h2
|
Windows Setup and Deployment Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43457
|
2024-09-18 01:25 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312262
|
7.7 |
HIGH
Network
|
microsoft
|
windows_10_1607 windows_server_2016
|
Windows Networking Information Disclosure Vulnerability
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-43458
|
2024-09-18 01:24 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312263
|
7.8 |
HIGH
Local
|
microsoft
|
visio 365_apps office office_long_term_servicing_channel
|
Microsoft Office Visio Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43463
|
2024-09-18 01:08 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312264
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_server_2016
|
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43467
|
2024-09-18 01:06 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312265
|
8.8 |
HIGH
Network
|
microsoft
|
azure_cyclecloud
|
Azure CycleCloud Remote Code Execution Vulnerability
|
CWE-94
Code Injection
|
CVE-2024-43469
|
2024-09-18 01:05 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312266
|
7.5 |
HIGH
Network
|
nac
|
nacpremium
|
Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data.This issue affects NACPremium: through 01082024.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-6921
|
2024-09-18 00:58 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312267
|
6.1 |
MEDIUM
Network
|
nac
|
nacpremium
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Stored XSS.This issue affects NACPremium: th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6920
|
2024-09-18 00:58 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312268
|
9.8 |
CRITICAL
Network
|
nac
|
nacpremium
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Blind SQL Injection.This issue affects NACPr…
|
CWE-89
SQL Injection
|
CVE-2024-6919
|
2024-09-18 00:57 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312269
|
6.5 |
MEDIUM
Network
|
siemens
|
omnivise_t3000_application_server
|
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow au…
|
CWE-22
Path Traversal
|
CVE-2024-38878
|
2024-09-18 00:50 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312270
|
9.8 |
CRITICAL
Network
|
anji-plus
|
report
|
anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitra…
|
NVD-CWE-Other
|
CVE-2024-7314
|
2024-09-18 00:45 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312271
|
7.8 |
HIGH
Local
|
siemens
|
omnivise_t3000_whitelisting_server omnivise_t3000_thin_client omnivise_t3000_terminal_server omnivise_t3000_product_data_management omnivise_t3000_domain_controller omnivise_t3000_appl…
|
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (…
|
NVD-CWE-noinfo
|
CVE-2024-38876
|
2024-09-17 23:45 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312272
|
9.8 |
CRITICAL
Network
|
totolink
|
t8_firmware
|
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-46419
|
2024-09-17 23:35 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312273
|
9.8 |
CRITICAL
Network
|
totolink
|
t8_firmware
|
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-46451
|
2024-09-17 23:35 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312274
|
7.5 |
HIGH
Network
|
totolink
|
t8_firmware
|
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-46424
|
2024-09-17 23:35 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312275
|
7.5 |
HIGH
Network
|
nt-ware
|
uniflow_smartclient uniflow_online_print_\&_scan uniflow_online
|
The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email…
|
NVD-CWE-Other
|
CVE-2024-1621
|
2024-09-17 23:12 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312276
|
7.8 |
HIGH
Local
|
vmware
|
fusion
|
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnera…
|
NVD-CWE-noinfo
|
CVE-2024-38811
|
2024-09-17 22:33 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312277
|
9.8 |
CRITICAL
Network
|
avtech
|
avm1203_firmware
|
Commands can be injected over the network and executed without authentication.
|
CWE-77
Command Injection
|
CVE-2024-7029
|
2024-09-17 22:30 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312278
|
7.8 |
HIGH
Local
|
w1.fi
|
wpa_supplicant
|
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplican…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-5290
|
2024-09-17 22:09 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312279
|
6.5 |
MEDIUM
Network
|
fish-shop
|
syntax-check
|
fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in the `pattern` input (specifically the command separator `;` and command substi…
|
NVD-CWE-Other
|
CVE-2024-42482
|
2024-09-17 21:20 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312280
|
7.8 |
HIGH
Local
|
nvidia
|
gpu_display_driver virtual_gpu cloud_gaming
|
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability m…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-0107
|
2024-09-17 21:10 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312281
|
7.1 |
HIGH
Local
|
huawei
|
emui harmonyos
|
Access control vulnerability in the security verification module
mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
|
NVD-CWE-noinfo
|
CVE-2024-42033
|
2024-09-17 21:06 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312282
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink: Initialise extack before use in ACKs
Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_EN…
|
NVD-CWE-noinfo
|
CVE-2024-44945
|
2024-09-17 20:42 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312283
|
8.8 |
HIGH
Network
|
syscomgo
|
omflow
|
OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regular privileges to update system settings or create…
|
NVD-CWE-Other
|
CVE-2024-8779
|
2024-09-17 20:27 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312284
|
9.8 |
CRITICAL
Network
|
code-projects
|
crud_operation_system
|
A vulnerability was found in code-projects Crud Operation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file savedata.php. The manipulation of the argum…
|
CWE-89
SQL Injection
|
CVE-2024-8868
|
2024-09-17 19:59 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312285
|
5.4 |
MEDIUM
Network
|
perfexcrm
|
perfex_crm
|
A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8867
|
2024-09-17 19:55 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312286
|
4.9 |
MEDIUM
Network
|
composio
|
composio
|
A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file composio\server\api.py. The manipulation of the arg…
|
CWE-22
Path Traversal
|
CVE-2024-8865
|
2024-09-17 19:50 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312287
|
8.8 |
HIGH
Network
|
composio
|
composio
|
A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculator of the file python/composio/tools/local/mathema…
|
CWE-94
Code Injection
|
CVE-2024-8864
|
2024-09-17 19:38 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312288
|
- |
-
|
-
|
-
|
Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.
|
-
|
CVE-2024-8039
|
2024-09-17 11:35 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312289
|
8.1 |
HIGH
Network
|
dell
|
smartfabric_os10
|
Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentia…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-39585
|
2024-09-17 11:15 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312290
|
8.8 |
HIGH
Network
|
-
|
-
|
Windows MSHTML Platform Spoofing Vulnerability
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2024-43461
|
2024-09-17 10:00 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312291
|
9.8 |
CRITICAL
Network
|
progress
|
whatsup_gold
|
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
|
CWE-89
SQL Injection
|
CVE-2024-6670
|
2024-09-17 10:00 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312292
|
8.8 |
HIGH
Network
|
asterisk
|
asterisk certified_asterisk
|
Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an A…
|
NVD-CWE-Other
|
CVE-2024-42365
|
2024-09-17 05:23 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312293
|
9.8 |
CRITICAL
Network
|
sonicwall
|
sonicos
|
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the fi…
|
NVD-CWE-noinfo
|
CVE-2024-40766
|
2024-09-17 04:48 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312294
|
8.8 |
HIGH
Network
|
xwiki
|
pro_macros
|
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform …
|
CWE-74
Injection
|
CVE-2024-42489
|
2024-09-17 04:46 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312295
|
5.5 |
MEDIUM
Local
|
nvidia
|
cuda_toolkit
|
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiving a user into reading a malformed ELF file. A successful…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-0102
|
2024-09-17 04:37 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312296
|
8.8 |
HIGH
Local
|
nvidia
|
jetson_linux
|
NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-0108
|
2024-09-17 04:27 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312297
|
7.5 |
HIGH
Network
|
nvidia
|
mlnx-os mlnx-gw onyx nvda-os_xc
|
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch…
|
NVD-CWE-Other
|
CVE-2024-0101
|
2024-09-17 04:24 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312298
|
8.8 |
HIGH
Network
|
solarwinds
|
access_rights_manager
|
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, r…
|
NVD-CWE-noinfo
|
CVE-2024-28991
|
2024-09-17 03:06 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312299
|
9.8 |
CRITICAL
Network
|
solarwinds
|
access_rights_manager
|
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-28990
|
2024-09-17 03:05 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312300
|
5.4 |
MEDIUM
Network
|
mindsdb
|
mindsdb
|
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, o…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45856
|
2024-09-17 03:04 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|