|
312601
|
6.1 |
MEDIUM
Network
|
gazelle_project
|
gazelle
|
A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …
|
CWE-79
Cross-site Scripting
|
CVE-2024-44793
|
2024-09-6 03:28 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312602
|
6.1 |
MEDIUM
Network
|
gazelle_project
|
gazelle
|
A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44795
|
2024-09-6 03:26 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312603
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: nl80211: disallow setting special AP channel widths
Setting the AP channel width is meant for use with the normal
20/40/...…
|
NVD-CWE-noinfo
|
CVE-2024-43912
|
2024-09-6 03:19 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312604
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nvme: apple: fix device reference counting
Drivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl.
Split the alloca…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-43913
|
2024-09-6 03:12 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312605
|
7.1 |
HIGH
Local
|
samsung
|
android
|
Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-34638
|
2024-09-6 03:05 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312606
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on…
|
NVD-CWE-Other
|
CVE-2024-34637
|
2024-09-6 03:05 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312607
|
4.6 |
MEDIUM
Physics
|
samsung
|
android
|
Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
|
CWE-22
Path Traversal
|
CVE-2024-34653
|
2024-09-6 03:04 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312608
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-34648
|
2024-09-6 03:04 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312609
|
3.3 |
LOW
Local
|
samsung
|
android
|
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
|
NVD-CWE-Other
|
CVE-2024-34640
|
2024-09-6 03:04 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312610
|
4.6 |
MEDIUM
Physics
|
samsung
|
android
|
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-34639
|
2024-09-6 03:04 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312611
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulner…
|
NVD-CWE-Other
|
CVE-2024-34644
|
2024-09-6 03:03 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312612
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vu…
|
NVD-CWE-Other
|
CVE-2024-34643
|
2024-09-6 03:03 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312613
|
4.6 |
MEDIUM
Physics
|
samsung
|
android
|
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34642
|
2024-09-6 03:03 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312614
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
md/raid5: avoid BUG_ON() while continue reshape after reassembling
Currently, mdadm support --revert-reshape to abort the reshape…
|
NVD-CWE-noinfo
|
CVE-2024-43914
|
2024-09-6 03:03 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312615
|
4.6 |
MEDIUM
Physics
|
samsung
|
android
|
Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.
|
NVD-CWE-noinfo
|
CVE-2024-34645
|
2024-09-6 03:02 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312616
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.
|
NVD-CWE-Other
|
CVE-2024-34646
|
2024-09-6 03:01 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312617
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.
|
NVD-CWE-noinfo
|
CVE-2024-34655
|
2024-09-6 03:00 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312618
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.
|
NVD-CWE-noinfo
|
CVE-2024-34654
|
2024-09-6 03:00 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312619
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
|
NVD-CWE-noinfo
|
CVE-2024-34647
|
2024-09-6 03:00 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312620
|
3.3 |
LOW
Local
|
samsung
|
android
|
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34652
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312621
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34651
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312622
|
3.3 |
LOW
Local
|
samsung
|
android
|
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34650
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312623
|
2.4 |
LOW
Physics
|
samsung
|
android
|
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.
|
NVD-CWE-Other
|
CVE-2024-34649
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312624
|
4.3 |
MEDIUM
Network
|
samsung
|
assistant
|
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerab…
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-34661
|
2024-09-6 02:57 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312625
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent possible UAF in ip6_xmit()
If skb_expand_head() returns NULL, skb has been freed
and the associated dst/idev could …
|
CWE-416
Use After Free
|
CVE-2024-44985
|
2024-09-6 02:54 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312626
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
workqueue: Fix UBSAN 'subtraction overflow' error in shift_and_mask()
UBSAN reports the following 'subtraction overflow' error wh…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-44981
|
2024-09-6 02:54 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312627
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()
bcm_sf2_mdio_register() calls of_phy_find_device() and t…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-44971
|
2024-09-6 02:54 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312628
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent UAF in ip6_send_skb()
syzbot reported an UAF in ip6_send_skb() [1]
After ip6_local_out() has returned, we no longe…
|
CWE-416
Use After Free
|
CVE-2024-44987
|
2024-09-6 02:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312629
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
power: supply: rt5033: Bring back i2c_set_clientdata
Commit 3a93da231c12 ("power: supply: rt5033: Use devm_power_supply_register(…
|
NVD-CWE-noinfo
|
CVE-2024-44936
|
2024-09-6 02:53 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312630
|
7.8 |
HIGH
Local
|
overwolf
|
overwolf
|
A local privilege escalation is caused by Overwolf
loading and executing certain dynamic link library files from a user-writeable
folder in SYSTEM context on launch. This allows an attacker with unpr…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-7834
|
2024-09-6 02:52 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312631
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path
Dan Carpenter reported a Smack static checker w…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-42307
|
2024-09-6 02:49 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312632
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: let's avoid panic if extent_tree is not created
This patch avoids the below panic.
pc : __lookup_extent_tree+0xd8/0x760
lr…
|
NVD-CWE-noinfo
|
CVE-2022-48877
|
2024-09-6 02:47 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312633
|
- |
-
|
-
|
-
|
A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handl…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2024-8462
|
2024-09-6 02:45 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312634
|
- |
-
|
-
|
-
|
SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.
|
-
|
CVE-2024-42885
|
2024-09-6 02:44 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312635
|
- |
-
|
-
|
-
|
itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.
|
-
|
CVE-2024-44587
|
2024-09-6 02:44 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312636
|
9.8 |
CRITICAL
Network
|
multivendorx
|
multivendorx
|
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation and account takeover due to an insufficient capab…
|
CWE-862
Missing Authorization
|
CVE-2024-8289
|
2024-09-6 02:41 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312637
|
6.1 |
MEDIUM
Network
|
raspcontrol_project
|
raspcontrol
|
Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/r…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8413
|
2024-09-6 02:40 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312638
|
6.8 |
MEDIUM
Adjacent
|
wayos
|
fbm-291w_firmware
|
WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.
|
CWE-77
Command Injection
|
CVE-2024-44383
|
2024-09-6 02:38 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312639
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix for possible memory corruption
Init Control Block is dereferenced incorrectly. Correctly dereference ICB
|
CWE-787
Out-of-bounds Write
|
CVE-2024-42288
|
2024-09-6 02:38 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312640
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: During vport delete send async logout explicitly
During vport delete, it is observed that during unload we hit a c…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-42289
|
2024-09-6 02:37 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312641
|
8.8 |
HIGH
Network
|
fogproject
|
fogproject
|
FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The Rebr…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-40645
|
2024-09-6 02:09 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312642
|
5.9 |
MEDIUM
Network
|
fogproject
|
fogproject
|
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only the host's mac address is required to obtain the c…
|
CWE-862
Missing Authorization
|
CVE-2024-41108
|
2024-09-6 01:27 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312643
|
7.8 |
HIGH
Local
|
fogproject
|
fogproject
|
FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable b…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-41954
|
2024-09-6 01:18 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312644
|
7.5 |
HIGH
Network
|
ruby-lang
|
rexml
|
REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-41946
|
2024-09-6 01:09 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312645
|
7.2 |
HIGH
Network
|
dell
|
cloudlink
|
CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could pote…
|
NVD-CWE-Other
|
CVE-2024-38482
|
2024-09-6 01:04 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312646
|
9.8 |
CRITICAL
Network
|
any1
|
neatvnc
|
server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type, a related issue to CVE-2006-2369.
|
NVD-CWE-noinfo
|
CVE-2024-42458
|
2024-09-6 00:51 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312647
|
5.4 |
MEDIUM
Network
|
metaphorcreations
|
ditty
|
The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2024-6710
|
2024-09-6 00:30 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312648
|
8.8 |
HIGH
Network
|
wpsoul
|
greenshift_query_addon
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift Query and Meta Addon allows SQL Injection.This issue affects Greenshift Query a…
|
CWE-89
SQL Injection
|
CVE-2024-43942
|
2024-09-6 00:25 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312649
|
8.8 |
HIGH
Network
|
wpsoul
|
greenshift_woocommerce_addon
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift Woocommerce Addon allows SQL Injection.This issue affects Greenshift Woocommerc…
|
CWE-89
SQL Injection
|
CVE-2024-43943
|
2024-09-6 00:10 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312650
|
8.8 |
HIGH
Network
|
wpmart
|
animated_number_counters
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated Number Counters allows PHP Local File Inclusion.This issue affects Animated Num…
|
CWE-22
Path Traversal
|
CVE-2024-43957
|
2024-09-5 23:49 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|