|
313351
|
- |
-
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site Scripting (XSS).This …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43317
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313352
|
- |
-
|
-
|
-
|
Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.
|
CWE-269
Improper Privilege Management
|
CVE-2024-43311
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313353
|
- |
-
|
-
|
-
|
In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerabil…
|
-
|
CVE-2024-42813
|
2024-08-21 00:44 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313354
|
- |
-
|
-
|
-
|
Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.
|
-
|
CVE-2024-42757
|
2024-08-21 00:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313355
|
- |
-
|
-
|
-
|
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature.
|
-
|
CVE-2024-27728
|
2024-08-20 23:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313356
|
5.4 |
MEDIUM
Network
|
mayurik
|
advocate_office_management_system
|
A vulnerability, which was classified as problematic, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the file register_case.php. The ma…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7686
|
2024-08-20 23:03 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313357
|
5.4 |
MEDIUM
Network
|
mayurik
|
advocate_office_management_system
|
A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the f…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7685
|
2024-08-20 22:53 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313358
|
5.4 |
MEDIUM
Network
|
mayurik
|
advocate_office_management_system
|
A vulnerability classified as problematic was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this vulnerability is an unknown functionality of the file add_act…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7684
|
2024-08-20 22:53 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313359
|
5.4 |
MEDIUM
Network
|
mayurik
|
advocate_office_management_system
|
A vulnerability classified as problematic has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file addcase_stage.php. The manipu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7683
|
2024-08-20 22:52 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313360
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
apparmor: Fix null pointer deref when receiving skb during sock creation
The panic below is observed when receiving ICMP packets …
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-52889
|
2024-08-20 06:19 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313361
|
9.8 |
CRITICAL
Network
|
angeljudesuarez
|
billing_system
|
A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part of the file addbill.php. The manipulation of the argument owners_id leads to sql…
|
CWE-89
SQL Injection
|
CVE-2024-7839
|
2024-08-20 06:18 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313362
|
5.4 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
|
CWE-79
Cross-site Scripting
|
CVE-2024-43810
|
2024-08-20 06:11 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313363
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
|
CWE-79
Cross-site Scripting
|
CVE-2024-43809
|
2024-08-20 06:11 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313364
|
5.4 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
|
CWE-79
Cross-site Scripting
|
CVE-2024-43808
|
2024-08-20 06:10 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313365
|
5.4 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
|
CWE-79
Cross-site Scripting
|
CVE-2024-43807
|
2024-08-20 06:09 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313366
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init().
ip6table_nat_table_init() accesses net->gen->ptr[…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-42269
|
2024-08-20 05:53 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313367
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix missing lock on sync reset reload
On sync reset reload work, when remote host updates devlink on reload
actions per…
|
CWE-667
Improper Locking
|
CVE-2024-42268
|
2024-08-20 05:52 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313368
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/v3d: Fix potential memory leak in the timestamp extension
If fetching of userspace memory fails during the main loop, all drm…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-42263
|
2024-08-20 05:41 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313369
|
- |
-
|
-
|
-
|
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execu…
|
-
|
CVE-2024-34743
|
2024-08-20 05:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313370
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-7958
|
2024-08-20 05:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313371
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/v3d: Fix potential memory leak in the performance extension
If fetching of userspace memory fails during the main loop, all d…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-42262
|
2024-08-20 05:05 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313372
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: fix use after free in iucv_sock_close()
iucv_sever_path() is called from process context and from bh context.
iucv->pat…
|
CWE-416
Use After Free
|
CVE-2024-42271
|
2024-08-20 05:03 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313373
|
7.8 |
HIGH
Local
|
ofono_project
|
ofono
|
oFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker m…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7547
|
2024-08-20 05:03 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313374
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init().
We had a report that iptables-restore sometimes triggered nu…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-42270
|
2024-08-20 05:01 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313375
|
7.8 |
HIGH
Local
|
ofono_project
|
ofono
|
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker mus…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7545
|
2024-08-20 05:00 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313376
|
7.8 |
HIGH
Local
|
ofono_project
|
ofono
|
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker mus…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7544
|
2024-08-20 05:00 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313377
|
7.8 |
HIGH
Local
|
ofono_project
|
ofono
|
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker mus…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7543
|
2024-08-20 04:59 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313378
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: nexthop: Initialize all fields in dumped nexthops
struct nexthop_grp contains two reserved fields that are not initialized b…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-42283
|
2024-08-20 04:54 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313379
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: mediatek: Fix potential NULL pointer dereference in dummy net_device handling
Move the freeing of the dummy net_device from …
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-42282
|
2024-08-20 04:53 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313380
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tipc: Return non-zero value from tipc_udp_addr2str() on error
tipc_udp_addr2str() should return non-zero value if the UDP media
a…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-42284
|
2024-08-20 04:47 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313381
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
RDMA/iwcm: Fix a use-after-free related to destroying CM IDs
iw_conn_req_handler() associates a new struct rdma_id_private (conn_…
|
CWE-416
Use After Free
|
CVE-2024-42285
|
2024-08-20 04:45 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313382
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
block: fix deadlock between sd_remove & sd_release
Our test report the following hung task:
[ 2538.459400] INFO: task "kworker/0…
|
CWE-667
Improper Locking
|
CVE-2024-42294
|
2024-08-20 04:43 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313383
|
9.8 |
CRITICAL
Network
|
projectworlds
|
online_examination_system
|
Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.
|
CWE-89
SQL Injection
|
CVE-2024-42843
|
2024-08-20 04:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313384
|
8.8 |
HIGH
Network
|
xuxueli
|
xxl-job
|
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-42681
|
2024-08-20 04:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313385
|
6.8 |
MEDIUM
Physics
|
dieboldnixdorf
|
vynamic_security_suite
|
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorizat…
|
NVD-CWE-noinfo
|
CVE-2023-24062
|
2024-08-20 04:05 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313386
|
6.8 |
MEDIUM
Physics
|
dieboldnixdorf
|
vynamic_security_suite
|
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot Authorization (PBA) process. This can…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2023-33206
|
2024-08-20 04:04 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313387
|
6.6 |
MEDIUM
Physics
|
dieboldnixdorf
|
vynamic_security_suite
|
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected has…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2023-28865
|
2024-08-20 04:04 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313388
|
6.8 |
MEDIUM
Physics
|
dieboldnixdorf
|
vynamic_security_suite
|
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able t…
|
NVD-CWE-noinfo
|
CVE-2023-24064
|
2024-08-20 04:04 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313389
|
6.8 |
MEDIUM
Physics
|
dieboldnixdorf
|
vynamic_security_suite
|
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2023-24063
|
2024-08-20 04:04 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313390
|
6.8 |
MEDIUM
Physics
|
dieboldnixdorf
|
vynamic_security_suite
|
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the Pre-Boot Authorization (PBA) process. T…
|
CWE-665
Improper Initialization
|
CVE-2023-40261
|
2024-08-20 04:03 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313391
|
7.8 |
HIGH
Local
|
adobe
|
dimension
|
Dimension versions 3.4.11 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi…
|
CWE-416
Use After Free
|
CVE-2024-20789
|
2024-08-20 03:59 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313392
|
5.5 |
MEDIUM
Local
|
adobe
|
dimension
|
Dimension versions 3.4.11 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mi…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-20790
|
2024-08-20 03:58 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313393
|
7.8 |
HIGH
Local
|
adobe
|
photoshop
|
Photoshop Desktop versions 24.7.3, 25.9.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …
|
CWE-416
Use After Free
|
CVE-2024-34117
|
2024-08-20 03:57 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313394
|
6.5 |
MEDIUM
Network
|
fortra
|
goanywhere_managed_file_transfer
|
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. …
|
CWE-287
Improper Authentication
|
CVE-2024-25157
|
2024-08-20 03:57 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313395
|
5.5 |
MEDIUM
Local
|
adobe
|
dimension
|
Dimension versions 3.4.11 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mi…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-34125
|
2024-08-20 03:56 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313396
|
7.8 |
HIGH
Local
|
adobe
|
dimension
|
Dimension versions 3.4.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-34124
|
2024-08-20 03:56 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313397
|
5.5 |
MEDIUM
Local
|
adobe
|
dimension
|
Dimension versions 3.4.11 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mi…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-34126
|
2024-08-20 03:55 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313398
|
7.8 |
HIGH
Local
|
adobe
|
bridge
|
Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-41840
|
2024-08-20 03:54 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313399
|
9.8 |
CRITICAL
Network
|
totolink
|
x6000r_firmware
|
A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. The manipulat…
|
CWE-77
Command Injection
|
CVE-2024-7907
|
2024-08-20 03:53 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313400
|
5.5 |
MEDIUM
Local
|
adobe
|
bridge
|
Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypa…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-39387
|
2024-08-20 03:53 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|