|
319101
|
5.5 |
MEDIUM
Local
|
apple
|
macos ipados iphone_os visionos watchos tvos
|
A file access issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, …
|
NVD-CWE-noinfo
|
CVE-2024-40850
|
2024-09-25 00:41 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319102
|
6.1 |
MEDIUM
Network
|
dedecms
|
dedecms
|
DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.
|
CWE-79
Cross-site Scripting
|
CVE-2024-46372
|
2024-09-25 00:40 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319103
|
6.5 |
MEDIUM
Network
|
acquia
|
mautic
|
Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing.
Users could potentially access sensitive data such a…
|
CWE-276
Incorrect Default Permissions
|
CVE-2022-25776
|
2024-09-25 00:19 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319104
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to modify protected parts of the file system.
|
NVD-CWE-noinfo
|
CVE-2024-40843
|
2024-09-25 00:02 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319105
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive data.
|
NVD-CWE-noinfo
|
CVE-2024-40842
|
2024-09-24 23:56 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319106
|
7.5 |
HIGH
Network
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify restricted network settings.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2024-40770
|
2024-09-24 23:55 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319107
|
8.1 |
HIGH
Network
|
micropython
|
micropython
|
A vulnerability was found in MicroPython 1.22.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file py/objarray.c. The manipulation leads to use …
|
CWE-416
Use After Free
|
CVE-2024-8947
|
2024-09-24 22:17 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319108
|
7.5 |
HIGH
Network
|
micropython
|
micropython
|
A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component VFS Unmount Handler. The manipula…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-8946
|
2024-09-24 22:11 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319109
|
7.8 |
HIGH
Local
|
microsoft
|
visio office 365_apps office_long_term_servicing_channel
|
Microsoft Office Visio Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38016
|
2024-09-24 20:11 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319110
|
4.3 |
MEDIUM
Physics
|
redhat opensc_project
|
enterprise_linux opensc
|
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially craft…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-45619
|
2024-09-24 08:26 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319111
|
7.2 |
HIGH
Network
|
acquia
|
mautic
|
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle.
The user could retrieve and alter data like sensitive data, login, and…
|
CWE-89
SQL Injection
|
CVE-2022-25775
|
2024-09-24 08:22 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319112
|
5.4 |
MEDIUM
Network
|
acquia
|
mautic
|
Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic.
Users could inject malicious code into the notification when sa…
|
CWE-79
Cross-site Scripting
|
CVE-2022-25774
|
2024-09-24 08:21 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319113
|
4.8 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS versions 9.0.0 through 9.3.3 are affected by a
stored XSS vulnerability in the "Top Navigator Bar" block.
Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue adm…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8660
|
2024-09-24 08:00 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319114
|
5.5 |
MEDIUM
Local
|
apple
|
visionos
|
The issue was addressed with improved handling of caches. This issue is fixed in visionOS 2. An app may be able to read sensitive data from the GPU memory.
|
NVD-CWE-noinfo
|
CVE-2024-40790
|
2024-09-24 07:55 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319115
|
- |
-
|
-
|
-
|
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects:
?Product
Affected Versions
LoadMaster
From 7.…
|
CWE-20
Improper Input Validation
|
CVE-2024-6658
|
2024-09-24 05:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319116
|
7.5 |
HIGH
Network
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to access the internet.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2024-27795
|
2024-09-24 05:01 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319117
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2024-27858
|
2024-09-24 04:56 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319118
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause a denial-of-service.
|
NVD-CWE-noinfo
|
CVE-2024-23237
|
2024-09-24 04:53 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319119
|
5.3 |
MEDIUM
Network
|
contao
|
contao
|
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to…
|
CWE-74
Injection
|
CVE-2024-45612
|
2024-09-24 04:33 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319120
|
6.1 |
MEDIUM
Local
|
apple
|
macos iphone_os ipados
|
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An unencrypted document may be written to a temporary file when using pri…
|
NVD-CWE-noinfo
|
CVE-2024-40826
|
2024-09-24 04:25 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319121
|
3.3 |
LOW
Local
|
apple
|
iphone_os ipados
|
This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to enumerate a user's installed apps.
|
NVD-CWE-noinfo
|
CVE-2024-40830
|
2024-09-24 04:19 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319122
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access a user's Photos Library.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2024-40831
|
2024-09-24 04:18 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319123
|
- |
-
|
-
|
-
|
An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 13…
|
-
|
CVE-2024-25073
|
2024-09-24 04:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319124
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An application may be able to read restricted memory.
|
NVD-CWE-noinfo
|
CVE-2024-27860
|
2024-09-24 04:10 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319125
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.
|
NVD-CWE-noinfo
|
CVE-2024-40837
|
2024-09-24 03:50 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319126
|
6.5 |
MEDIUM
Network
|
backstage
|
backstage
|
Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak …
|
CWE-22
Path Traversal
|
CVE-2024-45816
|
2024-09-24 03:41 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319127
|
6.5 |
MEDIUM
Network
|
backstage
|
backstage
|
Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the s…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2024-45815
|
2024-09-24 03:31 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319128
|
5.4 |
MEDIUM
Network
|
backstage
|
backstage
|
Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-46976
|
2024-09-24 03:27 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319129
|
6.1 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8907
|
2024-09-24 03:23 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319130
|
6.1 |
MEDIUM
Network
|
oretnom23
|
resort_reservation_system
|
A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_fee.php. The manipul…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8951
|
2024-09-24 03:12 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319131
|
7.5 |
HIGH
Network
|
micropython
|
micropython
|
A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffe…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-8948
|
2024-09-24 03:10 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319132
|
8.8 |
HIGH
Network
|
oretnom23
|
online_eyewear_shop
|
A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart Content Handler. Th…
|
CWE-282
Improper Ownership Management
|
CVE-2024-8949
|
2024-09-24 03:05 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319133
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
|
NVD-CWE-noinfo
|
CVE-2024-8908
|
2024-09-24 02:59 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319134
|
6.1 |
MEDIUM
Network
|
netcat
|
netcat_content_management_system
|
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site.
This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8653
|
2024-09-24 02:55 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319135
|
6.1 |
MEDIUM
Network
|
netcat
|
netcat_content_management_system
|
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site.
This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8652
|
2024-09-24 02:53 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319136
|
5.3 |
MEDIUM
Network
|
netcat
|
netcat_content_management_system
|
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks.
Th…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-8651
|
2024-09-24 02:51 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319137
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
|
NVD-CWE-noinfo
|
CVE-2024-8909
|
2024-09-24 02:51 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319138
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML p…
|
NVD-CWE-noinfo
|
CVE-2024-8906
|
2024-09-24 02:38 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319139
|
8.8 |
HIGH
Network
|
microsoft
|
sql_2016_azure_connect_feature_pack sql_server_2016 sql_server_2017 sql_server_2019 sql_server_2022
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37339
|
2024-09-24 02:34 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319140
|
8.8 |
HIGH
Network
|
microsoft
|
edge_chromium
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43489
|
2024-09-24 02:33 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319141
|
4.3 |
MEDIUM
Network
|
microsoft
|
edge_chromium
|
Microsoft Edge (Chromium-based) Spoofing Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38221
|
2024-09-24 02:33 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319142
|
8.8 |
HIGH
Network
|
microsoft
|
edge_chromium
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43496
|
2024-09-24 02:32 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319143
|
9.8 |
CRITICAL
Network
|
dlink
|
dar-7000_firmware
|
A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation of the a…
|
CWE-78
OS Command
|
CVE-2024-9004
|
2024-09-24 02:29 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319144
|
8.8 |
HIGH
Network
|
microsoft
|
sql_2016_azure_connect_feature_pack sql_server_2016 sql_server_2017 sql_server_2019 sql_server_2022
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37340
|
2024-09-24 02:08 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319145
|
8.8 |
HIGH
Network
|
microsoft
|
sql_2016_azure_connect_feature_pack sql_server_2016 sql_server_2017 sql_server_2019 sql_server_2022
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37338
|
2024-09-24 02:04 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319146
|
4.3 |
MEDIUM
Network
|
microsoft
|
sql_2016_azure_connect_feature_pack sql_server_2016 sql_server_2017 sql_server_2019 sql_server_2022
|
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37337
|
2024-09-24 02:00 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319147
|
8.8 |
HIGH
Network
|
microsoft
|
sql_2016_azure_connect_feature_pack sql_server_2016 sql_server_2017 sql_server_2019 sql_server_2022
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37335
|
2024-09-24 01:58 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319148
|
9.8 |
CRITICAL
Network
|
fabianros
|
hospital_management_system
|
A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affects an unknown part of the file check_availability.php. The manipulation of the …
|
CWE-89
SQL Injection
|
CVE-2024-8944
|
2024-09-24 01:56 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319149
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Check denominator crb_pipes before used
[WHAT & HOW]
A denominator cannot be 0, and is checked before used.
Thi…
|
CWE-369
Divide By Zero
|
CVE-2024-46772
|
2024-09-24 01:52 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319150
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Check denominator pbn_div before used
[WHAT & HOW]
A denominator cannot be 0, and is checked before used.
This …
|
CWE-369
Divide By Zero
|
CVE-2024-46773
|
2024-09-24 01:51 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|