|
312301
|
7.5 |
HIGH
Network
|
mindsdb
|
mindsdb
|
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘fi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-45855
|
2024-09-17 03:03 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312302
|
7.5 |
HIGH
Network
|
mindsdb
|
mindsdb
|
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘descri…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-45854
|
2024-09-17 03:02 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312303
|
7.5 |
HIGH
Network
|
mindsdb
|
mindsdb
|
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-45853
|
2024-09-17 02:59 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312304
|
8.8 |
HIGH
Network
|
mindsdb
|
mindsdb
|
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-45852
|
2024-09-17 02:51 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312305
|
5.5 |
MEDIUM
Local
|
adobe
|
indesign
|
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-34127
|
2024-09-17 02:48 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312306
|
8.8 |
HIGH
Network
|
mindsdb
|
mindsdb
|
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases crea…
|
CWE-94
Code Injection
|
CVE-2024-45851
|
2024-09-17 02:36 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312307
|
8.8 |
HIGH
Network
|
mindsdb
|
mindsdb
|
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases crea…
|
CWE-94
Code Injection
|
CVE-2024-45850
|
2024-09-17 02:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312308
|
8.8 |
HIGH
Network
|
mindsdb
|
mindsdb
|
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases crea…
|
CWE-94
Code Injection
|
CVE-2024-45849
|
2024-09-17 02:34 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312309
|
8.8 |
HIGH
Network
|
mindsdb
|
mindsdb
|
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘INSERT…
|
CWE-94
Code Injection
|
CVE-2024-45848
|
2024-09-17 02:33 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312310
|
8.8 |
HIGH
Network
|
mindsdb
|
mindsdb
|
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. If a specially crafted ‘UPD…
|
CWE-94
Code Injection
|
CVE-2024-45847
|
2024-09-17 02:31 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312311
|
8.8 |
HIGH
Network
|
mindsdb
|
mindsdb
|
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SELECT…
|
CWE-94
Code Injection
|
CVE-2024-45846
|
2024-09-17 02:30 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312312
|
5.4 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external acti…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45621
|
2024-09-17 02:28 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312313
|
5.4 |
MEDIUM
Network
|
elabftw
|
elabftw
|
eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a visitor's browser runs arbitrary JavaScript…
|
CWE-79
Cross-site Scripting
|
CVE-2024-28100
|
2024-09-17 02:28 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312314
|
- |
-
|
-
|
-
|
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.
|
CWE-1245
|
CVE-2024-24968
|
2024-09-17 02:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312315
|
- |
-
|
-
|
-
|
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-23984
|
2024-09-17 02:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312316
|
- |
-
|
-
|
-
|
Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access.
|
-
|
CVE-2024-23599
|
2024-09-17 02:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312317
|
- |
-
|
-
|
-
|
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-20
Improper Input Validation
|
CVE-2024-21871
|
2024-09-17 02:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312318
|
- |
-
|
-
|
-
|
Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-20
Improper Input Validation
|
CVE-2024-21829
|
2024-09-17 02:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312319
|
- |
-
|
-
|
-
|
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access.
|
CWE-20
Improper Input Validation
|
CVE-2024-21781
|
2024-09-17 02:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312320
|
- |
-
|
-
|
-
|
Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.
|
CWE-92
DEPRECATED: Improper Sanitization of Custom Special Characters
|
CVE-2023-43753
|
2024-09-17 02:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312321
|
- |
-
|
-
|
-
|
Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-284
Improper Access Control
|
CVE-2023-43626
|
2024-09-17 02:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312322
|
- |
-
|
-
|
-
|
Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2023-42772
|
2024-09-17 02:15 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312323
|
- |
-
|
-
|
-
|
A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-362
Race Condition
|
CVE-2023-41833
|
2024-09-17 02:15 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312324
|
- |
-
|
-
|
-
|
Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.
|
CWE-125
Out-of-bounds Read
|
CVE-2023-25546
|
2024-09-17 02:15 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312325
|
- |
-
|
-
|
-
|
NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-395
Use of NullPointerException Catch to Detect NULL Pointer Dereference
|
CVE-2023-23904
|
2024-09-17 02:15 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312326
|
- |
-
|
-
|
-
|
Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-787
Out-of-bounds Write
|
CVE-2023-22351
|
2024-09-17 02:15 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312327
|
9.8 |
CRITICAL
Network
|
ibm
|
sterling_connect_direct_web_services
|
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.
|
CWE-1392
Use of Default Credentials
|
CVE-2024-39747
|
2024-09-17 02:13 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312328
|
7.5 |
HIGH
Network
|
skyport
|
skyportd
|
Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skyport's lack of rate limiting on createFolder. createFile), skyportd in a lot of c…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-42481
|
2024-09-17 02:10 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312329
|
7.8 |
HIGH
Local
|
ultimaker
|
ultimaker_cura
|
UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from improper handling of th…
|
CWE-94
Code Injection
|
CVE-2024-8374
|
2024-09-17 01:44 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312330
|
6.4 |
MEDIUM
Network
|
halo
|
halo
|
Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43793
|
2024-09-17 01:28 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312331
|
6.1 |
MEDIUM
Network
|
halo
|
halo
|
Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vulnerability allows an attacker to execute malicious …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43792
|
2024-09-17 01:26 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312332
|
8.2 |
HIGH
Network
|
sap
|
bex_web_java_runtime_export_web_service
|
BEx Web Java Runtime Export Web Service does not
sufficiently validate an XML document accepted from an untrusted source. An
attacker can retrieve information from the SAP ADS system and exhaust the
…
|
CWE-91
Blind XPath Injection
|
CVE-2024-42374
|
2024-09-17 01:25 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312333
|
9.1 |
CRITICAL
Network
|
sap
|
commerce_cloud
|
Some OCC API endpoints in SAP Commerce Cloud
allows Personally Identifiable Information (PII) data, such as passwords, email
addresses, mobile numbers, coupon codes, and voucher codes, to be included…
|
NVD-CWE-noinfo
|
CVE-2024-33003
|
2024-09-17 01:22 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312334
|
7.5 |
HIGH
Network
|
github
|
actions\/artifact actions_toolkit
|
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` before 2.1.7 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downl…
|
CWE-22
Path Traversal
|
CVE-2024-42471
|
2024-09-17 01:18 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312335
|
4.3 |
MEDIUM
Network
|
sap
|
business_objects_business_intelligence_platform
|
SAP BusinessObjects Business Intelligence
Platform allows an authenticated attacker to upload malicious code over the
network, that could be executed by the application. On successful
exploitat…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-28166
|
2024-09-17 01:17 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312336
|
5.3 |
MEDIUM
Network
|
mainwww
|
mwcms
|
A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the function uploadeditor of the file /uploadeditor.html?action=uploadimage of the…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7705
|
2024-09-17 01:15 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312337
|
4.4 |
MEDIUM
Local
|
dell
|
insightiq
|
Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to D…
|
NVD-CWE-noinfo
|
CVE-2024-39574
|
2024-09-17 00:59 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312338
|
9.8 |
CRITICAL
Network
|
dell
|
insightiq
|
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially expl…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2024-39581
|
2024-09-17 00:50 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312339
|
5.5 |
MEDIUM
Local
|
dell
|
precision_7920_firmware 7920_xl_firmware
|
Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially ex…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2024-42425
|
2024-09-17 00:46 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312340
|
9.8 |
CRITICAL
Network
|
dell
|
insightiq
|
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploi…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2024-39583
|
2024-09-17 00:42 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312341
|
6.7 |
MEDIUM
Local
|
dell
|
insightiq
|
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, lead…
|
NVD-CWE-noinfo
|
CVE-2024-39580
|
2024-09-17 00:40 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312342
|
4.4 |
MEDIUM
Local
|
dell
|
insightiq
|
Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to In…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-39582
|
2024-09-17 00:36 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312343
|
6.5 |
MEDIUM
Network
|
snowflake
|
streamlit
|
Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. Users of hosted Stre…
|
CWE-22
Path Traversal
|
CVE-2024-42474
|
2024-09-16 23:30 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312344
|
4.3 |
MEDIUM
Network
|
ibm
|
openpages_grc_platform openpages_with_watson
|
IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users.
|
NVD-CWE-Other
|
CVE-2024-27257
|
2024-09-16 23:26 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312345
|
6.5 |
MEDIUM
Local
|
theforeman
|
foreman
|
A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page. This flaw allows an attacker with the ne…
|
CWE-77
Command Injection
|
CVE-2024-7700
|
2024-09-16 23:20 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312346
|
4.3 |
MEDIUM
Network
|
sap
|
oil_\%\/_gas
|
Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow…
|
CWE-862
Missing Authorization
|
CVE-2024-44112
|
2024-09-16 23:19 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312347
|
2.7 |
LOW
Network
|
sap
|
netweaver_application_server_abap
|
Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logged in as a developer to read objects contained in a package. This causes an impa…
|
CWE-862
Missing Authorization
|
CVE-2024-41728
|
2024-09-16 23:14 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312348
|
2.7 |
LOW
Network
|
sap
|
netweaver_application_server_abap
|
SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that reveals data over the network. This results in a minimal impact on confidentiali…
|
CWE-863
Incorrect Authorization
|
CVE-2024-44114
|
2024-09-16 23:09 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312349
|
5.4 |
MEDIUM
Network
|
jayesh
|
online_exam_system
|
A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1.0, which allows remote attackers to execute arbitrary code via "rname" and "em…
|
CWE-79
Cross-site Scripting
|
CVE-2024-40478
|
2024-09-16 22:46 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312350
|
8.8 |
HIGH
Network
|
elastic
|
kibana
|
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Secu…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-37288
|
2024-09-16 22:29 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|