|
312751
|
- |
-
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate h…
|
-
|
CVE-2022-4412
|
2024-08-31 06:15 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312752
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-42379
|
2024-08-31 05:15 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312753
|
- |
-
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate h…
|
-
|
CVE-2022-4540
|
2024-08-31 05:15 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312754
|
- |
-
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate h…
|
-
|
CVE-2022-4530
|
2024-08-31 05:15 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312755
|
- |
-
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate h…
|
-
|
CVE-2022-4424
|
2024-08-31 05:15 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312756
|
4.3 |
MEDIUM
Network
|
cyberark
|
identity
|
CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security
|
NVD-CWE-Other
|
CVE-2024-42340
|
2024-08-31 04:47 |
2024-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312757
|
4.3 |
MEDIUM
Network
|
cyberark
|
identity
|
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
|
NVD-CWE-noinfo
|
CVE-2024-42339
|
2024-08-31 04:47 |
2024-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312758
|
4.3 |
MEDIUM
Network
|
cyberark
|
identity
|
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
|
CWE-200
Information Exposure
|
CVE-2024-42338
|
2024-08-31 04:47 |
2024-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312759
|
6.5 |
MEDIUM
Network
|
cyberark
|
identity
|
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
|
CWE-200
Information Exposure
|
CVE-2024-42337
|
2024-08-31 04:47 |
2024-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312760
|
4.8 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code. The Concrete CMS security team gave this vu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7512
|
2024-08-31 03:19 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312761
|
4.8 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded into responses. A rogue administrator could inject mal…
|
CWE-79
Cross-site Scripting
|
CVE-2024-4350
|
2024-08-31 03:18 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312762
|
5.4 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus_msp manageengine_servicedesk_plus manageengine_supportcenter_plus
|
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-38869
|
2024-08-31 03:15 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312763
|
9.8 |
CRITICAL
Network
|
pimax
|
play pitool
|
Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.
|
NVD-CWE-Other
|
CVE-2024-41889
|
2024-08-31 02:53 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312764
|
8.0 |
HIGH
Adjacent
|
zexelon
|
zwx-2000csw2-hn_firmware
|
Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the con…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-41720
|
2024-08-31 02:49 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312765
|
8.8 |
HIGH
Adjacent
|
zexelon
|
zwx-2000csw2-hn_firmware
|
ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the devic…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-39838
|
2024-08-31 02:49 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312766
|
9.1 |
CRITICAL
Network
|
hamastar
|
meetinghub_paperless_meetings
|
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-6118
|
2024-08-31 02:44 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312767
|
8.8 |
HIGH
Network
|
hamastar
|
meetinghub_paperless_meetings
|
A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary sy…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-6117
|
2024-08-31 02:41 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312768
|
5.3 |
MEDIUM
Network
|
in2code
|
powermail
|
An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting in Insecure Direct Object Reference (IDOR). An un…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-45232
|
2024-08-31 01:34 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312769
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
CWE-843
Type Confusion
|
CVE-2024-8194
|
2024-08-31 01:34 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312770
|
9.8 |
CRITICAL
Network
|
in2code
|
powermail
|
An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, re…
|
NVD-CWE-Other
|
CVE-2024-45233
|
2024-08-31 01:33 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312771
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file
|
CWE-787
Out-of-bounds Write
|
CVE-2024-8250
|
2024-08-31 01:32 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312772
|
6.1 |
MEDIUM
Network
|
nextbricks
|
bricksore
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nextbricks Brickscore allows Stored XSS.This issue affects Brickscore: from n/a through 1.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43950
|
2024-08-31 01:20 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312773
|
7.5 |
HIGH
Network
|
frrouting redhat
|
frrouting enterprise_linux
|
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
|
NVD-CWE-noinfo
|
CVE-2024-44070
|
2024-08-31 01:19 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312774
|
5.4 |
MEDIUM
Network
|
cryoutcreations
|
tempera
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Tempera allows Stored XSS.This issue affects Tempera: from n/a through 1.8…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43951
|
2024-08-31 01:17 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312775
|
5.4 |
MEDIUM
Network
|
cryoutcreations
|
esotera
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Esotera allows Stored XSS.This issue affects Esotera: from n/a through 1.2…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43952
|
2024-08-31 01:16 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312776
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-8064
|
2024-08-31 01:15 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312777
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-7712
|
2024-08-31 01:15 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312778
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-7051
|
2024-08-31 01:15 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312779
|
6.1 |
MEDIUM
Network
|
gianniporto
|
intothedark
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gianni Porto IntoTheDark allows Reflected XSS.This issue affects IntoTheDark: from n/a thr…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43958
|
2024-08-31 01:15 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312780
|
6.5 |
MEDIUM
Network
|
stitionai
|
devika
|
stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with `HarmBlock…
|
CWE-74
Injection
|
CVE-2024-6331
|
2024-08-31 01:15 |
2024-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312781
|
4.8 |
MEDIUM
Network
|
pagebuilderaddons
|
web_and_woocommerce_addons_for_wpbakery_builder
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Page Builder Addons Web and WooCommerce Addons for WPBakery Builder allows Stored XSS.This…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43960
|
2024-08-31 01:12 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312782
|
6.1 |
MEDIUM
Network
|
waspthemes
|
yellowpencil
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects Ye…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43963
|
2024-08-31 01:10 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312783
|
7.5 |
HIGH
Network
|
ollama
|
ollama
|
extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.
|
CWE-22
Path Traversal
|
CVE-2024-45436
|
2024-08-31 01:08 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312784
|
7.2 |
HIGH
Network
|
lopalopa
|
responsive_school_management_system
|
A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the…
|
CWE-89
SQL Injection
|
CVE-2024-41236
|
2024-08-31 01:02 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312785
|
5.5 |
MEDIUM
Local
|
irfanview
|
irfanview
|
An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).
|
NVD-CWE-Other
|
CVE-2024-44915
|
2024-08-31 01:01 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312786
|
5.5 |
MEDIUM
Local
|
irfanview
|
irfanview
|
An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).
|
NVD-CWE-Other
|
CVE-2024-44914
|
2024-08-31 01:01 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312787
|
5.5 |
MEDIUM
Local
|
irfanview
|
irfanview
|
An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).
|
NVD-CWE-Other
|
CVE-2024-44913
|
2024-08-31 01:01 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312788
|
9.8 |
CRITICAL
Network
|
totolink
|
a3002r_firmware
|
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restricti…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-34195
|
2024-08-31 00:59 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312789
|
6.1 |
MEDIUM
Network
|
jupyter
|
jupyterlab notebook
|
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious n…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43805
|
2024-08-31 00:56 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312790
|
8.0 |
HIGH
Network
|
lopalopa
|
music_management_system
|
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.
|
CWE-352
Origin Validation Error
|
CVE-2024-42793
|
2024-08-31 00:56 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312791
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-8193
|
2024-08-31 00:52 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312792
|
9.8 |
CRITICAL
Network
|
sportsnet
|
sportsnet
|
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially…
|
CWE-89
SQL Injection
|
CVE-2024-29723
|
2024-08-31 00:51 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312793
|
9.8 |
CRITICAL
Network
|
sportsnet
|
sportsnet
|
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially…
|
CWE-89
SQL Injection
|
CVE-2024-29726
|
2024-08-31 00:50 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312794
|
9.8 |
CRITICAL
Network
|
sportsnet
|
sportsnet
|
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially…
|
CWE-89
SQL Injection
|
CVE-2024-29725
|
2024-08-31 00:50 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312795
|
9.8 |
CRITICAL
Network
|
sportsnet
|
sportsnet
|
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially…
|
CWE-89
SQL Injection
|
CVE-2024-29724
|
2024-08-31 00:50 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312796
|
9.8 |
CRITICAL
Network
|
menulux
|
managment_portal
|
Improper Privilege Management vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users.This issue affects Managment Portal: through 21.05.2024.
|
NVD-CWE-noinfo
|
CVE-2024-4428
|
2024-08-31 00:49 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312797
|
9.8 |
CRITICAL
Network
|
sportsnet
|
sportsnet
|
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially…
|
CWE-89
SQL Injection
|
CVE-2024-29731
|
2024-08-31 00:49 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312798
|
9.8 |
CRITICAL
Network
|
sportsnet
|
sportsnet
|
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially…
|
CWE-89
SQL Injection
|
CVE-2024-29730
|
2024-08-31 00:49 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312799
|
9.8 |
CRITICAL
Network
|
sportsnet
|
sportsnet
|
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially…
|
CWE-89
SQL Injection
|
CVE-2024-29729
|
2024-08-31 00:49 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312800
|
9.8 |
CRITICAL
Network
|
sportsnet
|
sportsnet
|
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially…
|
CWE-89
SQL Injection
|
CVE-2024-29728
|
2024-08-31 00:49 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|