|
312651
|
5.4 |
MEDIUM
Network
|
alwindoss
|
akademy
|
A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the f…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8407
|
2024-09-5 23:48 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312652
|
9.8 |
CRITICAL
Network
|
linksys
|
wrt54g_firmware
|
A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-8408
|
2024-09-5 23:41 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312653
|
6.1 |
MEDIUM
Network
|
zzcms
|
zzcms
|
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44819
|
2024-09-5 23:40 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312654
|
8.1 |
HIGH
Network
|
zyxel
|
zld_firmware
|
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) s…
|
CWE-78
OS Command
|
CVE-2024-42057
|
2024-09-5 23:40 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312655
|
6.1 |
MEDIUM
Network
|
semtekyazilim
|
semtek_sempos
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Reflected XSS.This issue affects…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7077
|
2024-09-5 23:39 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312656
|
9.8 |
CRITICAL
Network
|
semtekyazilim
|
semtek_sempos
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Blind SQL Injection.This issue a…
|
CWE-89
SQL Injection
|
CVE-2024-7076
|
2024-09-5 23:39 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312657
|
7.5 |
HIGH
Network
|
zyxel
|
zld_firmware
|
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware ver…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-42058
|
2024-09-5 23:39 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312658
|
4.3 |
MEDIUM
Network
|
discourse
|
discourse_calendar
|
discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topic. The limit on region value length is too generous. This allows a malicious ac…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-21658
|
2024-09-5 23:39 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312659
|
5.4 |
MEDIUM
Network
|
azurecurve
|
toggle_show\/hide
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in azurecurve azurecurve Toggle Show/Hide allows Stored XSS.This issue affects azurecurve Tog…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43961
|
2024-09-5 23:39 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312660
|
9.8 |
CRITICAL
Network
|
semtekyazilim
|
semtek_sempos
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows SQL Injection.This issue affects…
|
CWE-89
SQL Injection
|
CVE-2024-7078
|
2024-09-5 23:38 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312661
|
7.2 |
HIGH
Network
|
zyxel
|
zld_firmware
|
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG FLEX 50(W) series…
|
CWE-78
OS Command
|
CVE-2024-42059
|
2024-09-5 23:38 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312662
|
7.2 |
HIGH
Network
|
zyxel
|
zld_firmware
|
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series…
|
CWE-78
OS Command
|
CVE-2024-42060
|
2024-09-5 23:37 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312663
|
- |
-
|
-
|
-
|
Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.
|
-
|
CVE-2024-45692
|
2024-09-5 23:35 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312664
|
4.9 |
MEDIUM
Network
|
zyxel
|
zld_firmware
|
A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series fi…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-6343
|
2024-09-5 23:35 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312665
|
7.2 |
HIGH
Network
|
zyxel
|
zld_firmware
|
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an auth…
|
CWE-78
OS Command
|
CVE-2024-7203
|
2024-09-5 23:33 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312666
|
6.1 |
MEDIUM
Network
|
zyxel
|
zld_firmware
|
A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-42061
|
2024-09-5 23:32 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312667
|
9.8 |
CRITICAL
Network
|
linen
|
linen
|
Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.
|
NVD-CWE-Other
|
CVE-2024-45522
|
2024-09-5 23:29 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312668
|
7.5 |
HIGH
Network
|
linuxfoundation rdkcentral google
|
yocto rdk-b android
|
In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not nee…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-20089
|
2024-09-5 23:28 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312669
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not n…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-20088
|
2024-09-5 23:27 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312670
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-20087
|
2024-09-5 23:26 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312671
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-20086
|
2024-09-5 23:26 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312672
|
7.5 |
HIGH
Network
|
abcd-community
|
abcd
|
A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/php/otros_sitios.php. The manipulation of the argu…
|
CWE-22
Path Traversal
|
CVE-2024-8410
|
2024-09-5 23:20 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312673
|
7.5 |
HIGH
Network
|
abcd-community
|
abcd
|
A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_image.php. The manipulation of the argument image lead…
|
CWE-22
Path Traversal
|
CVE-2024-8409
|
2024-09-5 23:20 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312674
|
4.3 |
MEDIUM
Network
|
abcd-community
|
abcd
|
A vulnerability, which was classified as problematic, has been found in ABCD ABCD2 up to 2.2.0-beta-1. This issue affects some unknown processing of the file /buscar_integrada.php. The manipulation o…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8411
|
2024-09-5 23:19 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312675
|
7.8 |
HIGH
Local
|
yandex
|
yandex_browser
|
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
|
CWE-426
Untrusted Search Path
|
CVE-2024-6473
|
2024-09-5 23:19 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312676
|
9.6 |
CRITICAL
Adjacent
|
progress
|
openedge
|
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge …
|
CWE-94
Code Injection
|
CVE-2024-7345
|
2024-09-5 23:11 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312677
|
4.8 |
MEDIUM
Network
|
progress
|
openedge
|
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. This has been corrected so th…
|
CWE-287
Improper Authentication
|
CVE-2024-7346
|
2024-09-5 23:03 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312678
|
6.1 |
MEDIUM
Network
|
progress
|
openedge
|
An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated. Unauthorized access to the discovery service's U…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7654
|
2024-09-5 22:53 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312679
|
5.3 |
MEDIUM
Network
|
samsung
|
group_sharing
|
Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.
|
NVD-CWE-noinfo
|
CVE-2024-34659
|
2024-09-5 22:48 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312680
|
7.1 |
HIGH
Local
|
samsung
|
notes
|
Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-34658
|
2024-09-5 22:48 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312681
|
9.8 |
CRITICAL
Network
|
samsung
|
notes
|
Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-34657
|
2024-09-5 22:48 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312682
|
8.8 |
HIGH
Network
|
6shr_system_project
|
6shr_system
|
6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary syst…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8330
|
2024-09-5 22:41 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312683
|
8.8 |
HIGH
Network
|
6shr_system_project
|
6shr_system
|
6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database …
|
CWE-89
SQL Injection
|
CVE-2024-8329
|
2024-09-5 22:40 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312684
|
7.8 |
HIGH
Local
|
samsung
|
notes
|
Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-34660
|
2024-09-5 22:30 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312685
|
7.8 |
HIGH
Local
|
kingsoft
|
wps_office
|
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows libr…
|
CWE-22
Path Traversal
|
CVE-2024-7262
|
2024-09-5 22:30 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312686
|
6.5 |
MEDIUM
Network
|
wpextended
|
wp_extended
|
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via the download_file_ajax function. This makes …
|
CWE-22
Path Traversal
|
CVE-2024-8104
|
2024-09-5 22:28 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312687
|
8.8 |
HIGH
Network
|
wpextended
|
wp_extended
|
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the…
|
CWE-862
Missing Authorization
|
CVE-2024-8102
|
2024-09-5 22:28 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312688
|
6.5 |
MEDIUM
Network
|
wpextended
|
wp_extended
|
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. …
|
NVD-CWE-noinfo
|
CVE-2024-8106
|
2024-09-5 22:05 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312689
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
Input: MT - limit max slots
syzbot is reporting too large allocation at input_mt_init_slots(), for
num_slots is supplied from use…
|
-
|
CVE-2024-45008
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312690
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
char: xillybus: Don't destroy workqueue from work item running on it
Triggered by a kref decrement, destroy_workqueue() may be ca…
|
-
|
CVE-2024-45007
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312691
|
- |
-
|
-
|
-
|
A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system.
This vulnerability is due to inadequate a…
|
-
|
CVE-2024-20497
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312692
|
- |
-
|
-
|
-
|
Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where Ringer Server does not check to ensure that the user loa…
|
-
|
CVE-2024-45050
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312693
|
- |
-
|
-
|
-
|
Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.
|
-
|
CVE-2024-44859
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312694
|
- |
-
|
-
|
-
|
ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a …
|
-
|
CVE-2024-44821
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312695
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
x86/mtrr: Check if fixed MTRRs exist before saving them
MTRRs have an obsolete fixed variant for fine grained caching control
of …
|
-
|
CVE-2024-44948
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312696
|
- |
-
|
-
|
-
|
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component.
|
-
|
CVE-2024-44818
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312697
|
- |
-
|
-
|
-
|
SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.
|
-
|
CVE-2024-44817
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312698
|
- |
-
|
-
|
-
|
An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.
|
-
|
CVE-2024-44808
|
2024-09-5 21:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312699
|
- |
-
|
-
|
-
|
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
|
-
|
CVE-2024-6846
|
2024-09-5 15:15 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312700
|
- |
-
|
-
|
-
|
The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace.
Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to ac…
|
-
|
CVE-2024-43110
|
2024-09-5 14:15 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|