|
312801
|
5.4 |
MEDIUM
Network
|
etoilewebdesign
|
front_end_users
|
The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' shortcode in all versions up to, and including, 3.2.28 due to insufficient input s…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7606
|
2024-08-31 00:43 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312802
|
9.8 |
CRITICAL
Network
|
sportsnet
|
sportsnet
|
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially…
|
CWE-89
SQL Injection
|
CVE-2024-29727
|
2024-08-31 00:43 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312803
|
8.8 |
HIGH
Network
|
etoilewebdesign
|
front_end_users
|
The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.2.28 due to insufficient escaping on the user supp…
|
CWE-89
SQL Injection
|
CVE-2024-7607
|
2024-08-31 00:41 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312804
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The manipulation of the a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8294
|
2024-08-31 00:38 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312805
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbanner-create. The mani…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8295
|
2024-08-31 00:37 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312806
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation of the argument Use…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8296
|
2024-08-31 00:36 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312807
|
7.8 |
HIGH
Local
|
aertherwide
|
exiftags
|
Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-42851
|
2024-08-31 00:30 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312808
|
7.5 |
HIGH
Network
|
kitsada8621
|
digital_library_management_system
|
A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2024-8297
|
2024-08-31 00:28 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312809
|
9.8 |
CRITICAL
Network
|
gitapp
|
dingfanzu
|
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /aj…
|
CWE-89
SQL Injection
|
CVE-2024-8301
|
2024-08-31 00:24 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312810
|
4.8 |
MEDIUM
Adjacent
|
teldat
|
rs123_firmware rs123w_firmware
|
Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.
|
CWE-79
Cross-site Scripting
|
CVE-2022-39996
|
2024-08-31 00:17 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312811
|
4.3 |
MEDIUM
Network
|
smashballoon
|
reviews_feed
|
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i…
|
CWE-352
Origin Validation Error
|
CVE-2024-8200
|
2024-08-31 00:08 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312812
|
4.3 |
MEDIUM
Network
|
smashballoon
|
reviews_feed
|
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa…
|
CWE-862
Missing Authorization
|
CVE-2024-8199
|
2024-08-31 00:04 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312813
|
8.8 |
HIGH
Network
|
skyss
|
arfa-cms
|
A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.
|
CWE-352
Origin Validation Error
|
CVE-2024-45264
|
2024-08-31 00:02 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312814
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-846w_firmware
|
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.
|
CWE-78
OS Command
|
CVE-2024-44342
|
2024-08-30 23:57 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312815
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-846w_firmware
|
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST requ…
|
CWE-78
OS Command
|
CVE-2024-44341
|
2024-08-30 23:57 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312816
|
8.8 |
HIGH
Network
|
dlink
|
dir-846w_firmware
|
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.
|
CWE-78
OS Command
|
CVE-2024-44340
|
2024-08-30 23:56 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312817
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-846w_firmware
|
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.
|
CWE-78
OS Command
|
CVE-2024-41622
|
2024-08-30 23:55 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312818
|
6.5 |
MEDIUM
Network
|
ptc
|
thingworx
|
An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-40395
|
2024-08-30 23:35 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312819
|
- |
-
|
-
|
-
|
A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet…
|
CWE-94
Code Injection
|
CVE-2024-5651
|
2024-08-30 23:15 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312820
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commi…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2024-3114
|
2024-08-30 23:15 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312821
|
9.8 |
CRITICAL
Network
|
fortra
|
filecatalyst_workflow
|
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confi…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-6633
|
2024-08-30 23:11 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312822
|
7.2 |
HIGH
Network
|
fortra
|
filecatalyst_workflow
|
A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity, an…
|
CWE-89
SQL Injection
|
CVE-2024-6632
|
2024-08-30 23:07 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312823
|
9.8 |
CRITICAL
Network
|
brainlowcode
|
brain_low-code
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows S…
|
CWE-89
SQL Injection
|
CVE-2024-7071
|
2024-08-30 22:56 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312824
|
7.5 |
HIGH
Network
|
flowiseai
|
flowise
|
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supp…
|
NVD-CWE-noinfo
|
CVE-2024-8182
|
2024-08-30 22:53 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312825
|
6.7 |
MEDIUM
Local
|
mongodb
|
mongodb
|
In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cau…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2024-8207
|
2024-08-30 22:07 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312826
|
- |
-
|
-
|
-
|
An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected.
This is possible because the TAMPERRSTCAUSE register may not be…
|
-
|
CVE-2024-2502
|
2024-08-30 22:00 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312827
|
- |
-
|
-
|
-
|
A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. This affects an unknown part of the file /ajax/getBasicInfo.php. The manipulatio…
|
-
|
CVE-2024-8303
|
2024-08-30 22:00 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312828
|
- |
-
|
-
|
-
|
Rejected reason: Test CVE
|
-
|
CVE-2024-8333
|
2024-08-30 15:15 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312829
|
- |
-
|
-
|
-
|
The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.
|
-
|
CVE-2024-3673
|
2024-08-30 15:15 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312830
|
- |
-
|
-
|
-
|
One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). T…
|
-
|
CVE-2024-45488
|
2024-08-30 11:15 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312831
|
7.5 |
HIGH
Network
|
-
|
-
|
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allo…
|
CWE-78
OS Command
|
CVE-2024-8234
|
2024-08-30 10:15 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312832
|
- |
-
|
-
|
-
|
'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site ma…
|
-
|
CVE-2024-41918
|
2024-08-30 09:15 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312833
|
- |
-
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-50094. Reason: This candidate is a duplicate of CVE-2023-50094. Notes: All CVE users should reference CVE-2023-500…
|
-
|
CVE-2024-41661
|
2024-08-30 08:15 |
2024-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312834
|
9.8 |
CRITICAL
Network
|
totolink
|
t8_firmware
|
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been rated as critical. This issue affects the function exportOvpn. The manipulation leads to buffer overflow. The attack…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-8079
|
2024-08-30 07:00 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312835
|
9.8 |
CRITICAL
Network
|
totolink
|
t8_firmware
|
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been declared as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to buffer ove…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-8078
|
2024-08-30 07:00 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312836
|
9.8 |
CRITICAL
Network
|
totolink
|
t8_firmware
|
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os command injection. …
|
CWE-78
OS Command
|
CVE-2024-8077
|
2024-08-30 06:59 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312837
|
9.8 |
CRITICAL
Network
|
totolink
|
t8_firmware
|
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this issue is the function setDiagnosisCfg. The manipulation leads to buffer overflow. Th…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-8076
|
2024-08-30 06:58 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312838
|
9.8 |
CRITICAL
Network
|
totolink
|
t8_firmware
|
A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg. The manipulation leads to os com…
|
CWE-78
OS Command
|
CVE-2024-8075
|
2024-08-30 06:57 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312839
|
- |
-
|
-
|
-
|
The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on t…
|
-
|
CVE-2024-6460
|
2024-08-30 06:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312840
|
- |
-
|
-
|
-
|
TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from …
|
-
|
CVE-2024-34198
|
2024-08-30 05:36 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312841
|
5.5 |
MEDIUM
Local
|
ofono_project
|
ofono
|
oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authent…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-7537
|
2024-08-30 03:01 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312842
|
7.8 |
HIGH
Local
|
ofono_project
|
ofono
|
oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obt…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7539
|
2024-08-30 02:59 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312843
|
7.8 |
HIGH
Local
|
ofono_project
|
ofono
|
oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker mus…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7538
|
2024-08-30 02:59 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312844
|
3.3 |
LOW
Local
|
ofono_project
|
ofono
|
oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An a…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-7540
|
2024-08-30 02:58 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312845
|
3.3 |
LOW
Local
|
ofono_project
|
ofono
|
oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An at…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-7541
|
2024-08-30 02:57 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312846
|
3.3 |
LOW
Local
|
ofono_project
|
ofono
|
oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An a…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-7542
|
2024-08-30 02:56 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312847
|
7.8 |
HIGH
Local
|
ofono_project
|
ofono
|
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker mus…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7546
|
2024-08-30 02:55 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312848
|
5.4 |
MEDIUM
Network
|
haloservicesolutions
|
haloitsm
|
HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of the user accessing a ticket. …
|
CWE-79
Cross-site Scripting
|
CVE-2024-6200
|
2024-08-30 02:53 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312849
|
5.3 |
MEDIUM
Network
|
haloservicesolutions
|
haloitsm
|
HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive information. HaloIT…
|
NVD-CWE-Other
|
CVE-2024-6201
|
2024-08-30 02:52 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312850
|
9.8 |
CRITICAL
Network
|
haloservicesolutions
|
haloitsm
|
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM use…
|
CWE-863
Incorrect Authorization
|
CVE-2024-6202
|
2024-08-30 02:48 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|