|
313401
|
- |
-
|
-
|
-
|
A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of t…
|
CWE-378
Creation of Temporary File With Insecure Permissions
|
CVE-2024-7358
|
2024-08-2 01:45 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313402
|
- |
-
|
-
|
-
|
mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack.
|
-
|
CVE-2024-41262
|
2024-08-2 01:35 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313403
|
- |
-
|
-
|
-
|
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.
|
-
|
CVE-2024-41255
|
2024-08-2 00:35 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313404
|
- |
-
|
-
|
-
|
The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used again…
|
-
|
CVE-2024-6272
|
2024-08-2 00:35 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313405
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget wrapper link URL in all versions up to, and inclu…
|
-
|
CVE-2024-2455
|
2024-08-1 23:04 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313406
|
- |
-
|
-
|
-
|
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user re…
|
-
|
CVE-2024-6695
|
2024-08-1 23:00 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313407
|
- |
-
|
-
|
-
|
The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting att…
|
-
|
CVE-2024-6408
|
2024-08-1 23:00 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313408
|
- |
-
|
-
|
-
|
The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks ev…
|
-
|
CVE-2024-6165
|
2024-08-1 23:00 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313409
|
- |
-
|
-
|
-
|
os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an ELF file with a custom .interp secti…
|
-
|
CVE-2024-42381
|
2024-08-1 22:59 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313410
|
- |
-
|
-
|
-
|
goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.
|
-
|
CVE-2024-41253
|
2024-08-1 22:58 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313411
|
9.8 |
CRITICAL
Network
|
apple canonical
|
cups ubuntu_linux
|
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are…
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2004-2154
|
2024-08-1 22:41 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313412
|
- |
-
|
-
|
-
|
A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-7326
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313413
|
- |
-
|
-
|
-
|
Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.
|
-
|
CVE-2024-4187
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313414
|
- |
-
|
-
|
-
|
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-mi…
|
-
|
CVE-2024-41258
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313415
|
- |
-
|
-
|
-
|
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly…
|
-
|
CVE-2024-41256
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313416
|
7.8 |
HIGH
Local
|
-
|
-
|
A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated privileges.
|
-
|
CVE-2023-1577
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313417
|
2.7 |
LOW
Network
|
-
|
-
|
A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.
|
-
|
CVE-2022-4003
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313418
|
7.2 |
HIGH
Network
|
-
|
-
|
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
|
-
|
CVE-2022-4002
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313419
|
- |
-
|
-
|
-
|
An authentication bypass vulnerability could allow an attacker to access API functions without authentication.
|
-
|
CVE-2022-4001
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313420
|
7.8 |
HIGH
Local
|
-
|
-
|
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.
|
-
|
CVE-2019-6198
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313421
|
7.8 |
HIGH
Local
|
-
|
-
|
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.
|
-
|
CVE-2019-6197
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313422
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.
|
-
|
CVE-2017-3772
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313423
|
- |
-
|
-
|
-
|
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update…
|
-
|
CVE-2024-41955
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313424
|
- |
-
|
-
|
-
|
Pheonix App is a Python application designed to streamline various tasks, from managing files to playing mini-games. The issue is that the map of encoding/decoding languages are visible in code. The …
|
-
|
CVE-2024-41951
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313425
|
- |
-
|
-
|
-
|
slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp p…
|
-
|
CVE-2024-41660
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313426
|
- |
-
|
-
|
-
|
A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this vulnerability is an unknown functionality in the library madbasic_.bpl of the c…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-7324
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313427
|
- |
-
|
-
|
-
|
It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that i…
|
-
|
CVE-2024-23444
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313428
|
- |
-
|
-
|
-
|
Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate username…
|
-
|
CVE-2024-41952
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313429
|
- |
-
|
-
|
-
|
Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be entered by users or administr…
|
-
|
CVE-2024-41953
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313430
|
- |
-
|
-
|
-
|
Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let their users create and run Pipelin…
|
-
|
CVE-2024-41950
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313431
|
- |
-
|
-
|
-
|
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly t…
|
-
|
CVE-2024-39694
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313432
|
- |
-
|
-
|
-
|
The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload f…
|
-
|
CVE-2024-39318
|
2024-08-1 21:42 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313433
|
- |
-
|
-
|
-
|
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path …
|
-
|
CVE-2024-31201
|
2024-08-1 21:42 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313434
|
- |
-
|
-
|
-
|
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when a…
|
-
|
CVE-2024-31200
|
2024-08-1 21:42 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313435
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient …
|
-
|
CVE-2024-6208
|
2024-08-1 21:42 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313436
|
- |
-
|
-
|
-
|
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
|
-
|
CVE-2024-5678
|
2024-08-1 16:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313437
|
- |
-
|
-
|
-
|
The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be…
|
-
|
CVE-2024-6529
|
2024-08-1 15:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313438
|
- |
-
|
-
|
-
|
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some of its settings, which could all…
|
-
|
CVE-2024-4090
|
2024-08-1 15:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313439
|
- |
-
|
-
|
-
|
The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as d…
|
-
|
CVE-2024-3983
|
2024-08-1 15:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313440
|
- |
-
|
-
|
-
|
The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and upd…
|
-
|
CVE-2024-1747
|
2024-08-1 15:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313441
|
- |
-
|
-
|
-
|
A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7343
|
2024-08-1 14:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313442
|
- |
-
|
-
|
-
|
A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The man…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7342
|
2024-08-1 14:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313443
|
- |
-
|
-
|
-
|
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation o…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-7338
|
2024-08-1 13:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313444
|
- |
-
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function loginauth of the file /cgi-bin/cstecgi.cgi. The man…
|
-
|
CVE-2024-7337
|
2024-08-1 12:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313445
|
- |
-
|
-
|
-
|
A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation o…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-7336
|
2024-08-1 12:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313446
|
- |
-
|
-
|
-
|
A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipul…
|
-
|
CVE-2024-7335
|
2024-08-1 11:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313447
|
- |
-
|
-
|
-
|
A vulnerability was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. It has been rated as critical. This issue affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulati…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-7334
|
2024-08-1 11:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313448
|
- |
-
|
-
|
-
|
A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The ma…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-7333
|
2024-08-1 11:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313449
|
- |
-
|
-
|
-
|
OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execu…
|
-
|
CVE-2024-39607
|
2024-08-1 11:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313450
|
- |
-
|
-
|
-
|
Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an admin…
|
-
|
CVE-2024-34021
|
2024-08-1 11:15 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|