|
312551
|
8.8 |
HIGH
Network
|
ivanti
|
endpoint_manager
|
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
|
NVD-CWE-Other
|
CVE-2024-8322
|
2024-09-13 06:56 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312552
|
6.7 |
MEDIUM
Local
|
ivanti
|
endpoint_manager
|
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-8441
|
2024-09-13 06:53 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312553
|
8.6 |
HIGH
Network
|
ivanti
|
endpoint_manager
|
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-8321
|
2024-09-13 06:53 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312554
|
5.3 |
MEDIUM
Network
|
ivanti
|
endpoint_manager
|
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-8320
|
2024-09-13 06:51 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312555
|
9.8 |
CRITICAL
Network
|
ivanti
|
endpoint_manager
|
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
|
CWE-89
SQL Injection
|
CVE-2024-8191
|
2024-09-13 06:50 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312556
|
7.5 |
HIGH
Network
|
apollographql
|
apollo-router apollo_helms-charts_router apollo_router
|
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-43783
|
2024-09-13 06:33 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312557
|
7.5 |
HIGH
Network
|
apollographql
|
apollo_router apollo_helms-charts_router apollo-router apollo_query-planner apollo_gateway
|
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incre…
|
CWE-674
Uncontrolled Recursion
|
CVE-2024-43414
|
2024-09-13 06:33 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312558
|
5.4 |
MEDIUM
Network
|
wpmanageninja
|
ninja_tables
|
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7304
|
2024-09-13 06:32 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312559
|
5.4 |
MEDIUM
Network
|
jegtheme
|
jeg_elementor_kit
|
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and out…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6804
|
2024-09-13 06:31 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312560
|
8.8 |
HIGH
Network
|
naiches
|
dark_mode_for_wp_dashboard
|
Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.
|
CWE-352
Origin Validation Error
|
CVE-2024-43325
|
2024-09-13 06:28 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312561
|
4.3 |
MEDIUM
Network
|
checkoutplugins
|
stripe_payments_for_woocommerce
|
Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-43316
|
2024-09-13 06:26 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312562
|
5.4 |
MEDIUM
Network
|
fontsplugin
|
fonts_plugin
|
Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.
|
CWE-352
Origin Validation Error
|
CVE-2024-43301
|
2024-09-13 06:24 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312563
|
8.8 |
HIGH
Network
|
wpdeveloper
|
betterdocs
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through …
|
CWE-22
Path Traversal
|
CVE-2024-43129
|
2024-09-13 06:21 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312564
|
4.3 |
MEDIUM
Network
|
wpdataaccess
|
wp_data_access
|
Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This issue affects WP Data Access: from n/a through 5.5.7.
|
CWE-352
Origin Validation Error
|
CVE-2024-43295
|
2024-09-13 06:20 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312565
|
8.8 |
HIGH
Network
|
sendinblue
|
newsletter\ _smtp\ _email_marketing_and_subscribe
|
Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms b…
|
CWE-352
Origin Validation Error
|
CVE-2024-43287
|
2024-09-13 06:19 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312566
|
4.3 |
MEDIUM
Network
|
wpbackitup
|
backup_and_restore_wordpress
|
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.
|
CWE-352
Origin Validation Error
|
CVE-2024-43269
|
2024-09-13 06:18 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312567
|
8.8 |
HIGH
Network
|
themewinter
|
wpcafe
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through 2.2.28.
|
CWE-22
Path Traversal
|
CVE-2024-43135
|
2024-09-13 06:18 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312568
|
3.5 |
LOW
Network
|
analytify
|
analytify_-_google_analytics_dashboard
|
Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-43265
|
2024-09-13 06:17 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312569
|
7.5 |
HIGH
Network
|
storelocatorplus
|
store_locator_plus
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01.
|
NVD-CWE-noinfo
|
CVE-2024-43258
|
2024-09-13 06:11 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312570
|
8.8 |
HIGH
Network
|
mage-people
|
event_manager_and_tickets_selling_for_woocommerce
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event …
|
CWE-22
Path Traversal
|
CVE-2024-43138
|
2024-09-13 06:11 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312571
|
6.5 |
MEDIUM
Network
|
nouthemes
|
leopard
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36.
|
NVD-CWE-noinfo
|
CVE-2024-43257
|
2024-09-13 06:09 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312572
|
5.4 |
MEDIUM
Network
|
piotnet
|
piotnet_addons
|
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets in all versions up to,…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5502
|
2024-09-13 06:05 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312573
|
4.9 |
MEDIUM
Network
|
continew
|
continew_admin
|
A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /ap…
|
CWE-89
SQL Injection
|
CVE-2024-8150
|
2024-09-13 06:01 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312574
|
6.5 |
MEDIUM
Network
|
9front
|
lib9p
|
A bug in the 9p authentication implementation within lib9p allows an attacker with an existing valid user within the configured auth server to impersonate any other valid filesystem user.
This is du…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8158
|
2024-09-13 06:00 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312575
|
9.8 |
CRITICAL
Network
|
hillstonenet
|
web_application_firewall
|
Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firew…
|
CWE-77
Command Injection
|
CVE-2024-8073
|
2024-09-13 05:58 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312576
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
jfs: fix null ptr deref in dtInsertEntry
[syzbot reported]
general protection fault, probably for non-canonical address 0xdffffc0…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-44939
|
2024-09-13 05:58 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312577
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to cover read extent cache access with lock
syzbot reports a f2fs bug as below:
BUG: KASAN: slab-use-after-free in san…
|
CWE-416
Use After Free
|
CVE-2024-44941
|
2024-09-13 05:57 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312578
|
7.5 |
HIGH
Network
|
dfinity
|
canister_developer_kit_for_the_internet_computer
|
When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked a…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-7884
|
2024-09-13 05:47 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312579
|
8.8 |
HIGH
Network
|
mitel
|
mivoice_mx-one
|
The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successfu…
|
NVD-CWE-noinfo
|
CVE-2024-36446
|
2024-09-13 05:47 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312580
|
4.3 |
MEDIUM
Network
|
imagerecycle
|
imagerecycle_pdf_\&_image_compression
|
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and i…
|
CWE-862
Missing Authorization
|
CVE-2024-6631
|
2024-09-13 05:39 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312581
|
- |
-
|
-
|
-
|
The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks…
|
-
|
CVE-2024-7891
|
2024-09-13 05:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312582
|
6.5 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a…
|
CWE-74
Injection
|
CVE-2024-42903
|
2024-09-13 05:20 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312583
|
5.4 |
MEDIUM
Network
|
xibosignage
|
xibo
|
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43412
|
2024-09-13 05:20 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312584
|
6.1 |
MEDIUM
Network
|
syspass
|
syspass
|
A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Controllers/ClientCon…
|
CWE-79
Cross-site Scripting
|
CVE-2024-42904
|
2024-09-13 05:19 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312585
|
4.8 |
MEDIUM
Network
|
xibosignage
|
xibo
|
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43413
|
2024-09-13 05:18 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312586
|
5.4 |
MEDIUM
Network
|
cloudcannon
|
pagefinder
|
Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This information is gathered by looking …
|
CWE-79
Cross-site Scripting
|
CVE-2024-45389
|
2024-09-13 05:17 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312587
|
- |
-
|
-
|
-
|
Rejected reason: DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-45593. Reason: This record is a reservation duplicate of CVE-2024-45593. Notes: All CVE users should reference CVE-2024-45593 instea…
|
-
|
CVE-2024-45845
|
2024-09-13 05:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312588
|
9.8 |
CRITICAL
Network
|
blakeembrey
|
template
|
@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.…
|
CWE-94
Code Injection
|
CVE-2024-45390
|
2024-09-13 05:15 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312589
|
7.5 |
HIGH
Network
|
tina
|
tina
|
Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search toke…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-45391
|
2024-09-13 05:13 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312590
|
4.2 |
MEDIUM
Physics
|
yubico
|
yubikey_5c_nfc_firmware yubikey_5_nfc_firmware yubikey_5c_firmware yubikey_5_nano_firmware yubikey_5c_nano_firmware yubikey_5ci_firmware yubikey_5_nfc_fips_firmware yubikey_5c_nf…
|
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive eq…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-45678
|
2024-09-13 05:07 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312591
|
4.7 |
MEDIUM
Network
|
mozilla
|
firefox_focus
|
Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.
|
NVD-CWE-noinfo
|
CVE-2024-8399
|
2024-09-13 04:45 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312592
|
7.5 |
HIGH
Network
|
huawei
|
emui harmonyos
|
Access control vulnerability in the SystemUI module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
NVD-CWE-noinfo
|
CVE-2024-42039
|
2024-09-13 04:37 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312593
|
7.5 |
HIGH
Network
|
huawei
|
emui harmonyos
|
Input verification vulnerability in the system service module
Impact: Successful exploitation of this vulnerability will affect availability.
|
NVD-CWE-noinfo
|
CVE-2024-45441
|
2024-09-13 04:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312594
|
7.5 |
HIGH
Network
|
huawei
|
emui harmonyos
|
Permission control vulnerability in the software update module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
NVD-CWE-noinfo
|
CVE-2024-45450
|
2024-09-13 04:30 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312595
|
7.8 |
HIGH
Local
|
intel
|
tdx_module_software
|
Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local acces…
|
NVD-CWE-Other
|
CVE-2024-39283
|
2024-09-13 04:15 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312596
|
8.2 |
HIGH
Local
|
intel
|
nuc_x15_laptop_kit_lapbc510_firmware nuc_x15_laptop_kit_lapbc710_firmware nuc_x15_laptop_kit_lapac71g_firmware nuc_x15_laptop_kit_lapac71h_firmware nuc_x15_laptop_kit_lapkc51e_firmware
|
Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via local access.
|
NVD-CWE-noinfo
|
CVE-2024-34163
|
2024-09-13 03:59 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312597
|
7.8 |
HIGH
Local
|
intel
|
vtune_profiler oneapi_base_toolkit
|
Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-29015
|
2024-09-13 03:53 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312598
|
8.2 |
HIGH
Local
|
intel
|
server_board_s2600st_firmware
|
Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privil…
|
NVD-CWE-noinfo
|
CVE-2024-28947
|
2024-09-13 03:52 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312599
|
7.8 |
HIGH
Local
|
intel
|
oneapi_base_toolkit integrated_performance_primitives
|
Uncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-28887
|
2024-09-13 03:51 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312600
|
7.8 |
HIGH
Local
|
intel
|
nuc_x15_laptop_kit_lapac71h nuc_x15_laptop_kit_lapac71g nuc_x15_laptop_kit_lapkc71f nuc_x15_laptop_kit_lapkc71e nuc_x15_laptop_kit_lapkc51e nuc_m15_laptop_kit_lapbc710 nuc_m15_lapto…
|
Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local acc…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-25561
|
2024-09-13 03:50 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|