|
312501
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps office excel office_long_term_servicing_channel office_online_server
|
Microsoft Excel Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43465
|
2024-09-13 23:46 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312502
|
7.5 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Microsoft SharePoint Server Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43466
|
2024-09-13 23:44 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312503
|
7.3 |
HIGH
Network
|
microsoft
|
windows_server_2008
|
Microsoft Windows Admin Center Information Disclosure Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43475
|
2024-09-13 23:42 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312504
|
5.4 |
MEDIUM
Network
|
crocoblock
|
jetelements
|
The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 due to insufficient input sanitiz…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7144
|
2024-09-13 23:40 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312505
|
5.4 |
MEDIUM
Network
|
microsoft
|
dynamics_365
|
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
|
CWE-79
Cross-site Scripting
|
CVE-2024-43476
|
2024-09-13 23:39 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312506
|
8.8 |
HIGH
Network
|
crocoblock
|
jetelements
|
The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' parameter. This makes it possible for authenticated att…
|
CWE-22
Path Traversal
|
CVE-2024-7145
|
2024-09-13 23:39 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312507
|
8.5 |
HIGH
Network
|
microsoft
|
power_automate
|
Microsoft Power Automate Desktop Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43479
|
2024-09-13 23:38 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312508
|
4.3 |
MEDIUM
Network
|
bricksbuilder
|
bricks
|
The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' functio…
|
CWE-352
Origin Validation Error
|
CVE-2023-3408
|
2024-09-13 23:37 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312509
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: H…
|
CWE-416
Use After Free
|
CVE-2024-8639
|
2024-09-13 23:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312510
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
|
CWE-843
Type Confusion
|
CVE-2024-8638
|
2024-09-13 23:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312511
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severit…
|
CWE-416
Use After Free
|
CVE-2024-8637
|
2024-09-13 23:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312512
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
CWE-787
Out-of-bounds Write
|
CVE-2024-8636
|
2024-09-13 23:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312513
|
4.3 |
MEDIUM
Network
|
bricksbuilder
|
bricks
|
The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'reset_settings' functi…
|
CWE-352
Origin Validation Error
|
CVE-2023-3409
|
2024-09-13 23:34 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312514
|
5.4 |
MEDIUM
Network
|
cyberchimps
|
responsive_blocks
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue af…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43335
|
2024-09-13 23:25 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312515
|
5.4 |
MEDIUM
Network
|
bdthemes
|
ultimate_store_kit
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43342
|
2024-09-13 23:11 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312516
|
- |
-
|
-
|
-
|
A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP
address over Sopas ET.
This can lead to Denial of Service.
Users are recommended to upgrade both
MSC800 a…
|
-
|
CVE-2024-8751
|
2024-09-13 23:06 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312517
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: qgroup: do not warn on record without old_roots populated
[BUG]
There are some reports from the mailing list that since v6…
|
NVD-CWE-noinfo
|
CVE-2023-52897
|
2024-09-13 22:52 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312518
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
xhci: Fix null pointer dereference when host dies
Make sure xhci_free_dev() and xhci_kill_endpoint_urbs() do not race
and cause n…
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-52898
|
2024-09-13 22:46 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312519
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
Add exception protection processing for vd in axi_chan_handle_err function
Since there is no protection for vd, a kernel panic wi…
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-52899
|
2024-09-13 22:44 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312520
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix general protection fault in nilfs_btree_insert()
If nilfs2 reads a corrupted disk image and tries to reads a b-tree n…
|
NVD-CWE-noinfo
|
CVE-2023-52900
|
2024-09-13 22:40 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312521
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
usb: xhci: Check endpoint is valid before dereferencing it
When the host controller is not responding, all URBs queued to all
end…
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-52901
|
2024-09-13 22:37 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312522
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
io_uring: lock overflowing for IOPOLL
syzbot reports an issue with overflow filling for IOPOLL:
WARNING: CPU: 0 PID: 28 at io_ur…
|
CWE-667
Improper Locking
|
CVE-2023-52903
|
2024-09-13 22:34 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312523
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nommu: fix memory leak in do_mmap() error path
The preallocation of the maple tree nodes may leak if the error path to
"error_jus…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2023-52902
|
2024-09-13 22:29 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312524
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: Fix resource leakage in VF driver unbind
resources allocated like mcam entries to support the Ntuple feature
and ha…
|
NVD-CWE-Other
|
CVE-2023-52905
|
2024-09-13 22:27 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312525
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_mpls: Fix warning during failed attribute validation
The 'TCA_MPLS_LABEL' attribute is of 'NLA_U32' type, but has …
|
NVD-CWE-noinfo
|
CVE-2023-52906
|
2024-09-13 22:21 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312526
|
- |
-
|
-
|
-
|
Rejected reason: After careful review of CVE-2024-5203, it has been determined that the issue is not exploitable in real-world scenarios. Moreover, the exploit assumes that the attacker has access to…
|
-
|
CVE-2024-5203
|
2024-09-13 20:15 |
2024-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312527
|
9.8 |
CRITICAL
Network
|
learningdigital
|
orca_hcm
|
Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administ…
|
NVD-CWE-Other
|
CVE-2024-8584
|
2024-09-13 19:15 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312528
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Illustrator versions 28.6, 27.9.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to b…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-45111
|
2024-09-13 18:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312529
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Illustrator versions 28.6, 27.9.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulner…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-43759
|
2024-09-13 18:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312530
|
7.8 |
HIGH
Local
|
-
|
-
|
Illustrator versions 28.6, 27.9.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this iss…
|
CWE-416
Use After Free
|
CVE-2024-43758
|
2024-09-13 18:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312531
|
7.8 |
HIGH
Local
|
-
|
-
|
After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-41859
|
2024-09-13 18:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312532
|
5.5 |
MEDIUM
Local
|
-
|
-
|
After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-39382
|
2024-09-13 18:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312533
|
7.8 |
HIGH
Local
|
-
|
-
|
After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …
|
-
|
CVE-2024-39381
|
2024-09-13 18:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312534
|
- |
-
|
-
|
-
|
After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitati…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2024-39380
|
2024-09-13 18:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312535
|
7.8 |
HIGH
Local
|
adobe
|
illustrator
|
Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user…
|
NVD-CWE-noinfo
|
CVE-2024-41856
|
2024-09-13 18:15 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312536
|
5.4 |
MEDIUM
Network
|
3ds
|
3dexperience
|
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
|
CWE-79
Cross-site Scripting
|
CVE-2024-7939
|
2024-09-13 16:15 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312537
|
5.4 |
MEDIUM
Network
|
3ds
|
3dexperience
|
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
|
CWE-79
Cross-site Scripting
|
CVE-2024-7932
|
2024-09-13 16:15 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312538
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/mes: fix mes ring buffer overflow
wait memory room until enough before writing mes packets
to avoid ring buffer overfl…
|
-
|
CVE-2024-46700
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312539
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix potential UAF in nfsd4_cb_getattr_release
Once we drop the delegation reference, the fields embedded in it are no
longe…
|
-
|
CVE-2024-46696
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312540
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
firmware: qcom: scm: Mark get_wq_ctx() as atomic call
Currently get_wq_ctx() is wrongly configured as a standard call. When two
S…
|
-
|
CVE-2024-46692
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312541
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
gtp: fix a potential NULL pointer dereference
When sockfd_lookup() fails, gtp_encap_enable_socket() returns a
NULL pointer, but i…
|
-
|
CVE-2024-46677
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312542
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/v3d: Disable preemption while updating GPU stats
We forgot to disable preemption around the write_seqcount_begin/end() pair
w…
|
-
|
CVE-2024-46699
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312543
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
video/aperture: optionally match the device in sysfb_disable()
In aperture_remove_conflicting_pci_devices(), we currently only
ca…
|
-
|
CVE-2024-46698
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312544
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
soc: qcom: pmic_glink: Fix race during initialization
As pointed out by Stephen Boyd it is possible that during initialization
of…
|
-
|
CVE-2024-46693
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312545
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: Move unregister out of atomic section
Commit '9329933699b3 ("soc: qcom: pmic_glink: Make client-lock
non-sleepi…
|
-
|
CVE-2024-46691
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312546
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
usb: dwc3: st: fix probed platform device ref count on probe error path
The probe function never performs any paltform device all…
|
-
|
CVE-2024-46674
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312547
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
scsi: aacraid: Fix double-free on probe failure
aac_probe_one() calls hardware-specific init functions through the
aac_driver_ide…
|
-
|
CVE-2024-46673
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312548
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
nfsd: prevent panic for nfsv4.0 closed files in nfs4_show_open
Prior to commit 3f29cc82a84c ("nfsd: split sc_status out of
sc_typ…
|
-
|
CVE-2024-46682
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312549
|
- |
-
|
-
|
-
|
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain …
|
-
|
CVE-2024-38816
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312550
|
- |
-
|
-
|
-
|
In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in the kernel w…
|
-
|
CVE-2024-31336
|
2024-09-13 10:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|