|
313251
|
5.3 |
MEDIUM
Network
|
ltcms
|
ltcms
|
A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloadFile of the file /api/file/downloadfile of the component API Endpoint. The man…
|
CWE-22
Path Traversal
|
CVE-2024-7741
|
2024-08-22 04:07 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313252
|
9.8 |
CRITICAL
Network
|
ltcms
|
ltcms
|
A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical. This vulnerability affects the function download of the file /api/test/download of the component API Endpoint. Th…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-7740
|
2024-08-22 04:06 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313253
|
6.5 |
MEDIUM
Network
|
oretnom23
|
computer_laboratory_management_system
|
Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete ca…
|
NVD-CWE-noinfo
|
CVE-2024-41332
|
2024-08-22 03:53 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313254
|
9.8 |
CRITICAL
Network
|
tenda
|
fh1206_firmware
|
A vulnerability was found in Tenda FH1206 1.2.0.8. It has been declared as critical. Affected by this vulnerability is the function fromSafeClientFilter/fromSafeMacFilter/fromSafeUrlFilter. The manip…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7615
|
2024-08-22 03:48 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313255
|
9.8 |
CRITICAL
Network
|
tenda
|
fh1206_firmware
|
A vulnerability was found in Tenda FH1206 1.2.0.8(8155). It has been classified as critical. Affected is the function fromqossetting of the file /goform/qossetting. The manipulation of the argument p…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7614
|
2024-08-22 03:48 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313256
|
9.8 |
CRITICAL
Network
|
tenda
|
fh1206_firmware
|
A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of the argume…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7613
|
2024-08-22 03:47 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313257
|
- |
-
|
-
|
-
|
An issue in the downloader.php component of TOSEI online store management system v4.02, v4.03, and v4.04 allows attackers to execute a directory traversal.
|
-
|
CVE-2024-43022
|
2024-08-22 03:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313258
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.
|
CWE-352
Origin Validation Error
|
CVE-2024-42608
|
2024-08-22 03:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313259
|
8.8 |
HIGH
Network
|
siamonhasan
|
warehouse_inventory_system
|
A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
|
CWE-352
Origin Validation Error
|
CVE-2024-42579
|
2024-08-22 03:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313260
|
- |
-
|
-
|
-
|
In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede…
|
-
|
CVE-2024-20083
|
2024-08-22 03:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313261
|
8.8 |
HIGH
Network
|
ivanti
|
endpoint_manager_mobile
|
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the ap…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-36131
|
2024-08-22 03:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313262
|
9.6 |
CRITICAL
Network
|
koha
|
koha
|
Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component.
|
CWE-79
Cross-site Scripting
|
CVE-2024-28740
|
2024-08-22 03:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313263
|
- |
-
|
-
|
-
|
Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software
versions before 1.979. A physically close
attacker that is authenticated to the Blueto…
|
-
|
CVE-2024-40893
|
2024-08-22 03:15 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313264
|
- |
-
|
-
|
-
|
A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This vulnerability allows a physically close attacker to use the license UUID for authentication and provision …
|
-
|
CVE-2024-40892
|
2024-08-22 03:15 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313265
|
7.5 |
HIGH
Network
|
tenda
|
fh1201_firmware
|
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (Do…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-42950
|
2024-08-22 02:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313266
|
- |
-
|
-
|
-
|
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gai…
|
-
|
CVE-2024-43411
|
2024-08-22 02:25 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313267
|
- |
-
|
-
|
-
|
Russh is a Rust SSH client & server library. Allocating an untrusted amount of memory allows any unauthenticated user to OOM a russh server. An SSH packet consists of a 4-byte big-endian length, foll…
|
-
|
CVE-2024-43410
|
2024-08-22 02:25 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313268
|
- |
-
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Performance Center on Windows allows Cross-Site Scripting (XSS).This issue affect…
|
-
|
CVE-2022-26328
|
2024-08-22 02:25 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313269
|
- |
-
|
-
|
-
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive Data.This issue affects Performance Center: 12.63.
|
-
|
CVE-2022-26327
|
2024-08-22 02:25 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313270
|
- |
-
|
-
|
-
|
Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authenticatio…
|
CWE-89
SQL Injection
|
CVE-2024-5723
|
2024-08-22 02:24 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313271
|
- |
-
|
-
|
-
|
This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially leading …
|
-
|
CVE-2024-33657
|
2024-08-22 02:24 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313272
|
- |
-
|
-
|
-
|
The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escalation, arbitrary code execution, and bypassing OS s…
|
-
|
CVE-2024-33656
|
2024-08-22 02:24 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313273
|
- |
-
|
-
|
-
|
A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could all…
|
-
|
CVE-2024-20375
|
2024-08-22 02:24 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313274
|
9.8 |
CRITICAL
Network
|
arajajyothibabu
|
school_management_system
|
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.
|
CWE-89
SQL Injection
|
CVE-2024-42572
|
2024-08-22 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313275
|
- |
-
|
-
|
-
|
An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.
|
-
|
CVE-2024-42563
|
2024-08-22 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313276
|
- |
-
|
-
|
-
|
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.
|
-
|
CVE-2024-42556
|
2024-08-22 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313277
|
9.0 |
CRITICAL
Network
|
typecho
|
typecho
|
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2024-35540
|
2024-08-22 01:05 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313278
|
8.6 |
HIGH
Local
|
scilico
|
i-librarian
|
Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component.
|
CWE-79
Cross-site Scripting
|
CVE-2024-40500
|
2024-08-22 01:05 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313279
|
5.3 |
MEDIUM
Network
|
matrix
|
javascript_sdk
|
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's g…
|
CWE-674
Uncontrolled Recursion
|
CVE-2024-42369
|
2024-08-22 01:01 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313280
|
8.8 |
HIGH
Network
|
projectcapsule
|
capsule
|
Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e.,…
|
CWE-863
Incorrect Authorization
|
CVE-2024-39690
|
2024-08-22 01:01 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313281
|
5.4 |
MEDIUM
Network
|
3ds
|
3dexperience
|
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6378
|
2024-08-22 00:53 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313282
|
9.8 |
CRITICAL
Network
|
gotribe
|
gotribe-admin
|
A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file internal/app/routes/routes.go of the component Log…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-8003
|
2024-08-22 00:51 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313283
|
9.8 |
CRITICAL
Network
|
demozx
|
gf_cms
|
A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/auth/auth.go of the component JWT Authentication. T…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-8005
|
2024-08-22 00:49 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313284
|
9.8 |
CRITICAL
Network
|
newlib_project
|
newlib
|
An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-30949
|
2024-08-22 00:48 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313285
|
- |
-
|
-
|
-
|
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
|
-
|
CVE-2024-6843
|
2024-08-22 00:35 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313286
|
5.4 |
MEDIUM
Network
|
adonesevangelista
|
laravel_property_management_system
|
A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/no…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7945
|
2024-08-22 00:25 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313287
|
8.8 |
HIGH
Network
|
adonesevangelista
|
laravel_property_management_system
|
A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been classified as critical. Affected is the function UpdateDocumentsRequest of the file DocumentsController.p…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7944
|
2024-08-22 00:24 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313288
|
- |
-
|
-
|
-
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add
|
-
|
CVE-2024-42612
|
2024-08-21 23:35 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313289
|
8.8 |
HIGH
Network
|
siamonhasan
|
warehouse_inventory_system
|
A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
|
CWE-352
Origin Validation Error
|
CVE-2024-42577
|
2024-08-21 23:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313290
|
- |
-
|
-
|
-
|
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks…
|
-
|
CVE-2024-35539
|
2024-08-21 23:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313291
|
7.5 |
HIGH
Network
|
tamparongj_03
|
online_graduate_tracer_system
|
A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. The mani…
|
NVD-CWE-noinfo
|
CVE-2024-7843
|
2024-08-21 23:13 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313292
|
7.5 |
HIGH
Network
|
tamparongj_03
|
online_graduate_tracer_system
|
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the file /tracking/admin/export…
|
NVD-CWE-noinfo
|
CVE-2024-7842
|
2024-08-21 23:13 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313293
|
5.4 |
MEDIUM
Network
|
tamparongj_03
|
online_graduate_tracer_system
|
A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/admi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7844
|
2024-08-21 23:12 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313294
|
7.5 |
HIGH
Network
|
oretnom23
|
clinics_patient_management_system
|
A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerability affects unknown code of the file /pms/ajax/check_user_name.php. The manipu…
|
CWE-89
SQL Injection
|
CVE-2024-7841
|
2024-08-21 23:12 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313295
|
6.1 |
MEDIUM
Network
|
oretnom23
|
simple_forum_website
|
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects an unknown part of the file /registration.php of the component Signup Page. Th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7929
|
2024-08-21 23:10 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313296
|
8.8 |
HIGH
Network
|
oretnom23
|
clinic_patient_management_system
|
A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pms/ajax/get_packings.php. The …
|
CWE-89
SQL Injection
|
CVE-2024-7930
|
2024-08-21 23:09 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313297
|
8.8 |
HIGH
Network
|
tamparongj_03
|
online_graduate_tracer_system
|
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue affects some unknown processing of the file /tracking/admin/view_csprofile.php. Th…
|
CWE-89
SQL Injection
|
CVE-2024-7931
|
2024-08-21 23:08 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313298
|
9.8 |
CRITICAL
Network
|
adonesevangelista
|
online_blood_bank_management_system
|
A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file register.php of the …
|
CWE-89
SQL Injection
|
CVE-2024-7946
|
2024-08-21 22:55 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313299
|
9.8 |
CRITICAL
Network
|
janobe
|
point_of_sales_and_inventory_management_system
|
A vulnerability classified as critical has been found in SourceCodester Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the…
|
CWE-89
SQL Injection
|
CVE-2024-7947
|
2024-08-21 22:53 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313300
|
5.4 |
MEDIUM
Network
|
7-twenty
|
bot
|
7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
|
CWE-79
Cross-site Scripting
|
CVE-2024-42335
|
2024-08-21 22:49 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|