|
312351
|
6.1 |
MEDIUM
Network
|
uniong
|
webitr
|
WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, ca…
|
CWE-601
Open Redirect
|
CVE-2024-8586
|
2024-09-16 22:28 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312352
|
4.3 |
MEDIUM
Network
|
istyle
|
\@cosme
|
Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to …
|
NVD-CWE-noinfo
|
CVE-2024-45203
|
2024-09-16 22:27 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312353
|
9.8 |
CRITICAL
Network
|
project_team
|
tmall_demo
|
A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argu…
|
CWE-89
SQL Injection
|
CVE-2024-8568
|
2024-09-16 22:22 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312354
|
4.8 |
MEDIUM
Network
|
anujk305
|
bus_pass_management_system
|
phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44798
|
2024-09-16 22:19 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312355
|
7.8 |
HIGH
Local
|
adobe
|
illustrator
|
Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user.…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2024-41857
|
2024-09-16 22:18 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312356
|
5.5 |
MEDIUM
Local
|
adobe
|
premiere_pro
|
Premiere Pro versions 24.5, 23.6.8 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypas…
|
CWE-416
Use After Free
|
CVE-2024-39385
|
2024-09-16 22:12 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312357
|
7.8 |
HIGH
Local
|
adobe
|
premiere_pro
|
Premiere Pro versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of t…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-39384
|
2024-09-16 22:01 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312358
|
7.8 |
HIGH
Local
|
qnap
|
qts quts_hero
|
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to execute commands via unspe…
|
CWE-78 CWE-77
OS Command Command Injection
|
CVE-2024-38641
|
2024-09-16 21:35 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312359
|
7.8 |
HIGH
Local
|
qnap
|
qumagie
|
An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unsp…
|
CWE-295
Improper Certificate Validation
|
CVE-2024-38642
|
2024-09-16 21:33 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312360
|
5.4 |
MEDIUM
Network
|
qnap
|
download_station
|
A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We ha…
|
CWE-79
Cross-site Scripting
|
CVE-2024-38640
|
2024-09-16 21:27 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312361
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
vsock: fix recursive ->recvmsg calls
After a vsock socket has been added to a BPF sockmap, its prot->recvmsg
has been replaced wi…
|
CWE-674
Uncontrolled Recursion
|
CVE-2024-44996
|
2024-09-16 21:21 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312362
|
5.5 |
MEDIUM
Local
|
adobe
|
illustrator
|
Illustrator versions 28.5, 27.9.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to b…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-34134
|
2024-09-16 21:15 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312363
|
5.5 |
MEDIUM
Local
|
adobe
|
media_encoder
|
Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-41873
|
2024-09-16 20:39 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312364
|
5.5 |
MEDIUM
Local
|
adobe
|
media_encoder
|
Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-41872
|
2024-09-16 20:16 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312365
|
7.8 |
HIGH
Local
|
adobe
|
media_encoder
|
Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory struc…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-41871
|
2024-09-16 19:36 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312366
|
5.5 |
MEDIUM
Local
|
adobe
|
media_encoder
|
Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-41870
|
2024-09-16 19:32 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312367
|
7.8 |
HIGH
Local
|
adobe
|
media_encoder
|
Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-39377
|
2024-09-16 19:30 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312368
|
6.5 |
MEDIUM
Network
|
m-files
|
m-files_server
|
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
|
CWE-22
Path Traversal
|
CVE-2024-6789
|
2024-09-16 16:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312369
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: hns3: fix a deadlock problem when config TC during resetting
When config TC during the reset process, may cause a deadlock, …
|
CWE-667
Improper Locking
|
CVE-2024-44995
|
2024-09-16 03:15 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312370
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk()
[BUG]
There is an internal report that KASAN is repor…
|
CWE-415 CWE-416
Double Free Use After Free
|
CVE-2024-46687
|
2024-09-15 01:17 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312371
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
smb/client: avoid dereferencing rdata=NULL in smb2_new_read_req()
This happens when called from SMB2_read() while using rdma
and …
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46686
|
2024-09-15 01:16 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312372
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: single: fix potential NULL dereference in pcs_get_function()
pinmux_generic_get_function() can return NULL and the point…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46685
|
2024-09-15 01:00 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312373
|
9.8 |
CRITICAL
Network
|
code-projects
|
crud_operation_system
|
A vulnerability was found in code-projects Crud Operation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatedata.php. The manipulation of the argument si…
|
CWE-89
SQL Injection
|
CVE-2024-8762
|
2024-09-15 00:54 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312374
|
8.1 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to …
|
NVD-CWE-noinfo
|
CVE-2024-8754
|
2024-09-15 00:40 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312375
|
7.2 |
HIGH
Network
|
-
|
-
|
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input …
|
-
|
CVE-2024-8281
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312376
|
7.2 |
HIGH
Network
|
-
|
-
|
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service usin…
|
-
|
CVE-2024-8280
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312377
|
7.2 |
HIGH
Network
|
-
|
-
|
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
|
-
|
CVE-2024-8279
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312378
|
7.2 |
HIGH
Network
|
-
|
-
|
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
|
-
|
CVE-2024-8278
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312379
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
|
-
|
CVE-2024-8059
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312380
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.
|
-
|
CVE-2024-7756
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312381
|
6.7 |
MEDIUM
Local
|
-
|
-
|
A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.
|
-
|
CVE-2024-4550
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312382
|
6.7 |
MEDIUM
Local
|
-
|
-
|
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execu…
|
-
|
CVE-2024-45105
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312383
|
6.8 |
MEDIUM
Network
|
-
|
-
|
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince …
|
-
|
CVE-2024-45101
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312384
|
- |
-
|
-
|
-
|
A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.
|
-
|
CVE-2024-3100
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312385
|
- |
-
|
-
|
-
|
The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response protocol. However, there's an observed anomaly in the H2-DM1E PLC's protocol execu…
|
CWE-384
Session Fixation
|
CVE-2024-45368
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312386
|
- |
-
|
-
|
-
|
The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to ma…
|
-
|
CVE-2024-43099
|
2024-09-14 20:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312387
|
7.5 |
HIGH
Network
|
fastadmin
|
fastadmin
|
A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipula…
|
CWE-22
Path Traversal
|
CVE-2024-7928
|
2024-09-14 06:33 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312388
|
9.8 |
CRITICAL
Network
|
eyecix
|
jobsearch_wp_job_board
|
Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-43931
|
2024-09-14 06:22 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312389
|
5.4 |
MEDIUM
Network
|
qnap
|
notes_station_3
|
A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We hav…
|
CWE-79
Cross-site Scripting
|
CVE-2024-27122
|
2024-09-14 06:16 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312390
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
|
-
|
CVE-2024-40430
|
2024-09-14 06:15 |
2024-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312391
|
8.8 |
HIGH
Network
|
qnap
|
qts quts_hero
|
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
QuTSclou…
|
CWE-78
OS Command
|
CVE-2023-34974
|
2024-09-14 06:14 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312392
|
6.2 |
MEDIUM
Local
|
huawei
|
emui harmonyos
|
Vulnerability of uncaught exceptions in the Graphics module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
NVD-CWE-noinfo
|
CVE-2024-42037
|
2024-09-14 06:13 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312393
|
6.1 |
MEDIUM
Network
|
qnap
|
qulog_center
|
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a network.
We have already fixed t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-32762
|
2024-09-14 06:10 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312394
|
7.5 |
HIGH
Network
|
huawei
|
harmonyos emui
|
Access permission verification vulnerability in the Notepad module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
NVD-CWE-noinfo
|
CVE-2024-42036
|
2024-09-14 06:09 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312395
|
9.8 |
CRITICAL
Network
|
wpwebelite
|
docket
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This iss…
|
CWE-89
SQL Injection
|
CVE-2024-43132
|
2024-09-14 06:07 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312396
|
4.8 |
MEDIUM
Network
|
qnap
|
helpdesk
|
A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network.
We h…
|
CWE-79
Cross-site Scripting
|
CVE-2024-27125
|
2024-09-14 06:06 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312397
|
7.2 |
HIGH
Network
|
salonbookingsystem
|
salon_booking_system
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking System Salon booking system allows SQL Injection.This issue affects Salon booking s…
|
CWE-89
SQL Injection
|
CVE-2024-39658
|
2024-09-14 06:04 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312398
|
9.8 |
CRITICAL
Network
|
e4jconnect
|
vikrentcar
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E4J s.R.L. VikRentCar allows SQL Injection.This issue affects VikRentCar: from n/a through 1.4.0.
|
CWE-89
SQL Injection
|
CVE-2024-39653
|
2024-09-14 06:03 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312399
|
8.8 |
HIGH
Network
|
roundupwp
|
registrations_for_the_events_calendar
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registra…
|
CWE-89
SQL Injection
|
CVE-2024-39638
|
2024-09-14 06:00 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312400
|
8.8 |
HIGH
Network
|
pricelisto
|
great_restaurant_menu_wp
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Restaurant Menu by PriceListo allows SQL Injection.This issue affects Best Restau…
|
CWE-89
SQL Injection
|
CVE-2024-38793
|
2024-09-14 05:57 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|