|
313301
|
9.8 |
CRITICAL
Network
|
vonets
|
var1200-h_firmware var1200-l_firmware var600-h_firmware vap11ac_firmware vap11g-500s_firmware vbg1200_firmware vap11s-5g_firmware vap11s_firmware var11n-300_firmware vap11g…
|
Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and WiFi bridge repeaters, software versions
3.3.23.6.9 and prior, enables an unauthenticated remote attack…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-41161
|
2024-08-21 02:09 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313302
|
5.5 |
MEDIUM
Local
|
huawei
|
emui harmonyos
|
Access permission verification vulnerability in the Contacts module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
NVD-CWE-noinfo
|
CVE-2024-42032
|
2024-08-21 01:58 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313303
|
7.5 |
HIGH
Network
|
huawei
|
emui harmonyos
|
Access permission verification vulnerability in the Settings module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
NVD-CWE-noinfo
|
CVE-2024-42031
|
2024-08-21 01:57 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313304
|
6.2 |
MEDIUM
Local
|
huawei
|
harmonyos emui
|
Access permission verification vulnerability in the content sharing pop-up module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
NVD-CWE-noinfo
|
CVE-2024-42030
|
2024-08-21 01:55 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313305
|
9.8 |
CRITICAL
Network
|
vonets
|
var1200-h_firmware var1200-l_firmware var600-h_firmware vap11ac_firmware vap11g-500s_firmware vbg1200_firmware vap11s-5g_firmware vap11s_firmware var11n-300_firmware vap11g…
|
An improper authentication vulnerability affecting Vonets
industrial wifi bridge relays and wifi bridge repeaters, software versions
3.3.23.6.9 and prior enables an unauthenticated remote a…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2024-42001
|
2024-08-21 01:37 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313306
|
- |
-
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
|
-
|
CVE-2024-42586
|
2024-08-21 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313307
|
- |
-
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
|
-
|
CVE-2024-42585
|
2024-08-21 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313308
|
- |
-
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
|
-
|
CVE-2024-42576
|
2024-08-21 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313309
|
- |
-
|
-
|
-
|
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.
|
-
|
CVE-2024-42569
|
2024-08-21 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313310
|
- |
-
|
-
|
-
|
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.
|
-
|
CVE-2024-42562
|
2024-08-21 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313311
|
- |
-
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts or HT…
|
-
|
CVE-2024-42560
|
2024-08-21 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313312
|
- |
-
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
|
-
|
CVE-2024-42555
|
2024-08-21 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313313
|
- |
-
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
|
-
|
CVE-2024-42553
|
2024-08-21 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313314
|
7.5 |
HIGH
Network
|
vonets
|
var1200-h_firmware var1200-l_firmware var600-h_firmware vap11ac_firmware vap11g-500s_firmware vbg1200_firmware vap11s-5g_firmware vap11s_firmware var11n-300_firmware vap11g…
|
A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9
and prior, enables an unauthenticated remote attacker to re…
|
CWE-22
Path Traversal
|
CVE-2024-41936
|
2024-08-21 01:26 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313315
|
7.8 |
HIGH
Local
|
paloaltonetworks
|
globalprotect
|
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-5915
|
2024-08-21 01:23 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313316
|
9.8 |
CRITICAL
Network
|
paloaltonetworks
|
cortex_xsoar_commonscripts
|
A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.
|
CWE-77
Command Injection
|
CVE-2024-5914
|
2024-08-21 01:22 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313317
|
9.8 |
CRITICAL
Network
|
opensecurity
|
mobile_security_framework
|
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static L…
|
CWE-22
Path Traversal
|
CVE-2024-43399
|
2024-08-21 01:21 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313318
|
9.8 |
CRITICAL
Network
|
dell
|
dns-120_firmware dnr-202l_firmware dns-315l_firmware dns-320_firmware dns-320l_firmware dns-320lw_firmware dns-321_firmware dnr-322l_firmware dns-323_firmware dns-325_firmw…
|
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, …
|
CWE-77
Command Injection
|
CVE-2024-7922
|
2024-08-21 01:20 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313319
|
7.5 |
HIGH
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the clea…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-38891
|
2024-08-21 01:19 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313320
|
8.8 |
HIGH
Network
|
linksys
|
e1500_firmware
|
A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root pri…
|
CWE-78
OS Command
|
CVE-2024-42633
|
2024-08-21 01:18 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313321
|
7.5 |
HIGH
Network
|
nissan-global
|
blind_spot_protection_sensor_ecu_firmware
|
Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2024-6348
|
2024-08-21 01:17 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313322
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the databas…
|
CWE-78
OS Command
|
CVE-2024-38887
|
2024-08-21 01:17 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313323
|
7.8 |
HIGH
Local
|
google
|
android
|
In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
|
CWE-416
Use After Free
|
CVE-2024-32927
|
2024-08-21 01:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313324
|
7.5 |
HIGH
Network
|
nepstech
|
ntpl-xpon1gfevn_firmware
|
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2024-42657
|
2024-08-21 01:13 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313325
|
5.9 |
MEDIUM
Network
|
google haxx
|
nest_mini_firmware libcurl
|
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services …
|
NVD-CWE-noinfo
|
CVE-2024-32928
|
2024-08-21 01:13 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313326
|
9.8 |
CRITICAL
Network
|
nepstech
|
ntpl-xpon1gfevn_firmware
|
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
|
NVD-CWE-noinfo
|
CVE-2024-42658
|
2024-08-21 01:12 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313327
|
5.4 |
MEDIUM
Network
|
xwiki
|
xwiki
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a pa…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43400
|
2024-08-21 01:10 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313328
|
8.0 |
HIGH
Network
|
xwiki
|
xwiki
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a conten…
|
CWE-862
Missing Authorization
|
CVE-2024-43401
|
2024-08-21 01:09 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313329
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path travers…
|
CWE-22
Path Traversal
|
CVE-2024-7924
|
2024-08-21 01:07 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313330
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome …
|
NVD-CWE-noinfo
|
CVE-2024-7925
|
2024-08-21 01:06 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313331
|
4.8 |
MEDIUM
Network
|
fastadmin
|
fastadmin
|
A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7453
|
2024-08-21 00:50 |
2024-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313332
|
- |
-
|
-
|
-
|
CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability
exists that could cause a crash of the Accutech Manager when receiving a specially crafted
request over p…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-6918
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313333
|
- |
-
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
|
-
|
CVE-2024-42578
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313334
|
- |
-
|
-
|
-
|
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.
|
-
|
CVE-2024-42571
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313335
|
- |
-
|
-
|
-
|
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.
|
-
|
CVE-2024-42561
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313336
|
- |
-
|
-
|
-
|
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.
|
-
|
CVE-2024-42554
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313337
|
- |
-
|
-
|
-
|
Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can lead to denial of service which may result in servi…
|
-
|
CVE-2024-25009
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313338
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘close_text’ parameter in…
|
-
|
CVE-2024-7054
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313339
|
- |
-
|
-
|
-
|
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privilege…
|
-
|
CVE-2024-28829
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313340
|
- |
-
|
-
|
-
|
This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server.
This RCE (Rem…
|
-
|
CVE-2024-21689
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313341
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carousel_skin' attribute within the plugin's Course Carousel widget in all versions up…
|
-
|
CVE-2024-5576
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313342
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.7.5. This is due to missing or incorrect nonce validation on the bps_aja…
|
-
|
CVE-2024-7850
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313343
|
8.8 |
HIGH
Network
|
-
|
-
|
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient …
|
-
|
CVE-2024-7827
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313344
|
- |
-
|
-
|
-
|
A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensit…
|
-
|
CVE-2024-7305
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313345
|
- |
-
|
-
|
-
|
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
|
-
|
CVE-2024-4785
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313346
|
- |
-
|
-
|
-
|
Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-I…
|
-
|
CVE-2024-35538
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313347
|
- |
-
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in myCred allows Object Injection.This issue affects myCred: from n/a through 2.7.2.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-43354
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313348
|
- |
-
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects Landing Page Builder:…
|
CWE-22
Path Traversal
|
CVE-2024-43345
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313349
|
- |
-
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through …
|
CWE-22
Path Traversal
|
CVE-2024-43328
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313350
|
- |
-
|
-
|
-
|
Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through 1.2.7.
|
CWE-862
Missing Authorization
|
CVE-2024-43326
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|