|
313201
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
remoteproc: imx_rproc: Skip over memory region when node value is NULL
In imx_rproc_addr_init() "nph = of_count_phandle_with_args…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-43860
|
2024-08-23 02:08 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313202
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
PCI/DPC: Fix use-after-free on concurrent DPC and hot-removal
Keith reports a use-after-free when a DPC event occurs concurrently…
|
CWE-416
Use After Free
|
CVE-2024-42302
|
2024-08-23 01:37 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313203
|
- |
-
|
-
|
-
|
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.c…
|
-
|
CVE-2024-43033
|
2024-08-23 01:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313204
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
dev/parport: fix the array out-of-bounds risk
Fixed array out-of-bounds issues caused by sprintf
by replacing it with snprintf fo…
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-42301
|
2024-08-23 01:31 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313205
|
- |
-
|
-
|
-
|
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set …
|
-
|
CVE-2024-41659
|
2024-08-23 01:15 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313206
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
media: venus: fix use after free in vdec_close
There appears to be a possible use after free with vdec_close().
The firmware will…
|
CWE-416
Use After Free
|
CVE-2024-42313
|
2024-08-23 01:01 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313207
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes
In cdv_intel_lvds_get_modes(), the return value of drm_mode_…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-42310
|
2024-08-23 01:01 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313208
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes
In psb_intel_lvds_get_modes(), the return value of drm_mode_…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-42309
|
2024-08-23 01:01 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313209
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mm/mglru: fix div-by-zero in vmpressure_calc_level()
evict_folios() uses a second pass to reclaim folios that have gone through
p…
|
CWE-369
Divide By Zero
|
CVE-2024-42316
|
2024-08-23 00:52 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313210
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
exfat: fix potential deadlock on __exfat_get_dentry_set
When accessing a file with more entries than ES_MAX_ENTRY_NUM, the bh-arr…
|
CWE-667
Improper Locking
|
CVE-2024-42315
|
2024-08-23 00:51 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313211
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix null pointer dereference in resolve_prog_type() for BPF_PROG_TYPE_EXT
When loading a EXT program without specifying `att…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-43837
|
2024-08-23 00:44 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313212
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: ethtool: pse-pd: Fix possible null-deref
Fix a possible null dereference when a PSE supports both c33 and PoDL, but
only one…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-43836
|
2024-08-23 00:43 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313213
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
media: v4l: async: Fix NULL pointer dereference in adding ancillary links
In v4l2_async_create_ancillary_links(), ancillary links…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-43833
|
2024-08-23 00:42 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313214
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ext4: fix infinite loop when replaying fast_commit
When doing fast_commit replay an infinite loop may occur due to an
uninitializ…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2024-43828
|
2024-08-23 00:41 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313215
|
- |
-
|
-
|
-
|
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a me…
|
-
|
CVE-2024-45169
|
2024-08-23 00:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313216
|
- |
-
|
-
|
-
|
The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, a…
|
-
|
CVE-2024-45163
|
2024-08-23 00:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313217
|
- |
-
|
-
|
-
|
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.
|
-
|
CVE-2024-42552
|
2024-08-23 00:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313218
|
9.8 |
CRITICAL
Network
|
secom
|
dr.id_access_control
|
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database cont…
|
CWE-89
SQL Injection
|
CVE-2024-7731
|
2024-08-22 23:40 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313219
|
9.8 |
CRITICAL
Network
|
traccar
|
traccar
|
Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by …
|
CWE-287
Improper Authentication
|
CVE-2024-7746
|
2024-08-22 23:40 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313220
|
5.5 |
MEDIUM
Local
|
fortinet
|
fortios
|
An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained wri…
|
NVD-CWE-Other
|
CVE-2024-36505
|
2024-08-22 23:36 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313221
|
- |
-
|
-
|
-
|
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. Thus, communication endpoints are not verifiable.
|
-
|
CVE-2024-45168
|
2024-08-22 23:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313222
|
- |
-
|
-
|
-
|
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a me…
|
-
|
CVE-2024-45166
|
2024-08-22 23:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313223
|
9.8 |
CRITICAL
Network
|
arajajyothibabu
|
school_management_system
|
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.
|
CWE-89
SQL Injection
|
CVE-2024-42573
|
2024-08-22 23:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313224
|
7.8 |
HIGH
Local
|
fortinet
|
fortimanager fortianalyzer
|
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 t…
|
NVD-CWE-Other
|
CVE-2024-21757
|
2024-08-22 23:34 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313225
|
9.0 |
CRITICAL
Network
|
fortinet
|
fortisoar
|
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web scri…
|
CWE-79
Cross-site Scripting
|
CVE-2023-26211
|
2024-08-22 23:33 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313226
|
8.8 |
HIGH
Network
|
fortinet
|
fortios fortipam fortiswitchmanager fortiproxy
|
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 al…
|
CWE-613
Insufficient Session Expiration
|
CVE-2022-45862
|
2024-08-22 23:32 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313227
|
7.8 |
HIGH
Local
|
fortinet
|
fortiddos-f fortiddos
|
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0,…
|
CWE-78
OS Command
|
CVE-2022-27486
|
2024-08-22 23:29 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313228
|
7.1 |
HIGH
Network
|
pepperl-fuchs
|
icdm-rx\/tcp_socketserver_firmware profinet_firmware profinet\/modbus_firmware modbus_router_firmware modbus_server_firmware modbus_tcp_firmware ethernet\/ip_firmware eip\/modbus…
|
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
|
CWE-79
Cross-site Scripting
|
CVE-2024-5849
|
2024-08-22 22:39 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313229
|
7.1 |
HIGH
Network
|
pepperl-fuchs
|
icdm-rx\/tcp_socketserver_firmware profinet_firmware profinet\/modbus_firmware modbus_router_firmware modbus_server_firmware modbus_tcp_firmware ethernet\/ip_firmware eip\/modbus…
|
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
|
CWE-79
Cross-site Scripting
|
CVE-2024-38502
|
2024-08-22 22:35 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313230
|
6.1 |
MEDIUM
Network
|
pepperl-fuchs
|
icdm-rx\/tcp_socketserver_firmware profinet_firmware profinet\/modbus_firmware modbus_router_firmware modbus_server_firmware modbus_tcp_firmware ethernet\/ip_firmware eip\/modbus…
|
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
|
CWE-79
Cross-site Scripting
|
CVE-2024-38501
|
2024-08-22 22:34 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313231
|
7.2 |
HIGH
Network
|
elastic
|
kibana
|
A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototyp…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2024-37287
|
2024-08-22 22:33 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313232
|
7.5 |
HIGH
Network
|
ibm
|
openbmc
|
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-35124
|
2024-08-22 22:31 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313233
|
7.5 |
HIGH
Network
|
ibm
|
common_licensing
|
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.
|
CWE-521
Weak Password Requirements
|
CVE-2024-40697
|
2024-08-22 22:27 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313234
|
2.7 |
LOW
Network
|
mainwww
|
mwcms
|
A vulnerability was found in Fujian mwcms 1.0.0. It has been rated as critical. Affected by this issue is the function uploadimage of the file /uploadfile.html. The manipulation of the argument upfil…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7706
|
2024-08-22 22:26 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313235
|
9.8 |
CRITICAL
Network
|
tenda
|
fh1206_firmware
|
A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function formSafeEmailFilter of the file /goform/SafeEmailFilter of the component HTTP …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7707
|
2024-08-22 22:23 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313236
|
- |
-
|
-
|
-
|
Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.
|
CWE-862
Missing Authorization
|
CVE-2024-43331
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313237
|
- |
-
|
-
|
-
|
Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-39576
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313238
|
- |
-
|
-
|
-
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and…
|
-
|
CVE-2024-20486
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313239
|
- |
-
|
-
|
-
|
Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks.
These vulnerabilities are due…
|
-
|
CVE-2024-20417
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313240
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2022-48900
|
2024-08-22 17:15 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313241
|
7.8 |
HIGH
Local
|
kingsoft
|
wps_office
|
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows libr…
|
CWE-22
Path Traversal
|
CVE-2024-7263
|
2024-08-22 15:15 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313242
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-42143
|
2024-08-22 09:15 |
2024-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313243
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-37353
|
2024-08-22 09:15 |
2024-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313244
|
9.8 |
CRITICAL
Network
|
jayesh
|
online_exam_system
|
A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator…
|
NVD-CWE-Other
|
CVE-2024-40480
|
2024-08-22 06:35 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313245
|
- |
-
|
-
|
-
|
Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.
|
-
|
CVE-2024-41630
|
2024-08-22 06:35 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313246
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3
|
CWE-352
Origin Validation Error
|
CVE-2024-42604
|
2024-08-22 05:35 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313247
|
8.8 |
HIGH
Network
|
tamparongj_03
|
online_graduate_tracer_system
|
A vulnerability, which was classified as critical, was found in SourceCodester Online Graduate Tracer System up to 1.0. Affected is an unknown function of the file /tracking/admin/fetch_genderit.php.…
|
CWE-89
SQL Injection
|
CVE-2024-7949
|
2024-08-22 04:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313248
|
9.8 |
CRITICAL
Network
|
totolink
|
ex1200l_firmware
|
A vulnerability has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023 and classified as critical. Affected by this vulnerability is the function setLanguageCfg of the file /www/cgi-bin/cstecgi.cgi…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7909
|
2024-08-22 04:15 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313249
|
9.8 |
CRITICAL
Network
|
ltcms
|
ltcms
|
A vulnerability was found in wanglongcn ltcms 1.0.20. It has been declared as critical. Affected by this vulnerability is the function downloadUrl of the file /api/file/downloadUrl of the component A…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-7743
|
2024-08-22 04:15 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313250
|
9.8 |
CRITICAL
Network
|
ltcms
|
ltcms
|
A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical. Affected is the function multiDownload of the file /api/file/multiDownload of the component API Endpoint. The…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-7742
|
2024-08-22 04:08 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|