|
319551
|
- |
-
|
-
|
-
|
Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2021-38023
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319552
|
- |
-
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields messa…
|
-
|
CVE-2024-46639
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319553
|
- |
-
|
-
|
-
|
Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.
|
-
|
CVE-2024-44540
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319554
|
- |
-
|
-
|
-
|
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.
|
-
|
CVE-2024-39843
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319555
|
- |
-
|
-
|
-
|
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.
|
-
|
CVE-2024-39842
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319556
|
- |
-
|
-
|
-
|
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process th…
|
-
|
CVE-2024-39342
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319557
|
- |
-
|
-
|
-
|
A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.js…
|
-
|
CVE-2023-46948
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319558
|
- |
-
|
-
|
-
|
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthor…
|
-
|
CVE-2024-9014
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319559
|
- |
-
|
-
|
-
|
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote att…
|
-
|
CVE-2024-40442
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319560
|
- |
-
|
-
|
-
|
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote att…
|
-
|
CVE-2024-40441
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319561
|
- |
-
|
-
|
-
|
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.
|
-
|
CVE-2024-41228
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319562
|
- |
-
|
-
|
-
|
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.
|
-
|
CVE-2024-34331
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319563
|
- |
-
|
-
|
-
|
Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony…
|
-
|
CVE-2024-23934
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319564
|
- |
-
|
-
|
-
|
Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations…
|
-
|
CVE-2024-23933
|
2024-09-26 22:32 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319565
|
- |
-
|
-
|
-
|
PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.
|
-
|
CVE-2024-46241
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319566
|
- |
-
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Informatics Software Ferry Reservation System allows Reflected XSS.This issue affect…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7835
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319567
|
- |
-
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Exnet Informatics Software Ferry Reservation System allows SQL Injection.This issue affects Ferry…
|
CWE-89
SQL Injection
|
CVE-2024-7735
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319568
|
- |
-
|
-
|
-
|
Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38…
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2024-8903
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319569
|
- |
-
|
-
|
-
|
YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ attackers to inject arbi…
|
-
|
CVE-2024-7846
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319570
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
media: vivid: fix compose size exceed boundary
syzkaller found a bug:
BUG: unable to handle page fault for address: ffffc9000a3…
|
-
|
CVE-2022-48945
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319571
|
- |
-
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inclusion.This issue affects ElementsKit Pro: from n/…
|
CWE-22
Path Traversal
|
CVE-2024-43996
|
2024-09-26 22:32 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319572
|
- |
-
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated use…
|
-
|
CVE-2024-47226
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319573
|
- |
-
|
-
|
-
|
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTT…
|
-
|
CVE-2024-47220
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319574
|
- |
-
|
-
|
-
|
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
|
-
|
CVE-2024-47219
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319575
|
- |
-
|
-
|
-
|
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.
|
-
|
CVE-2024-47218
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319576
|
- |
-
|
-
|
-
|
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
|
-
|
CVE-2024-47210
|
2024-09-26 22:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319577
|
- |
-
|
-
|
-
|
eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
|
-
|
CVE-2024-46649
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319578
|
- |
-
|
-
|
-
|
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.
|
-
|
CVE-2024-46648
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319579
|
- |
-
|
-
|
-
|
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
|
-
|
CVE-2024-46647
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319580
|
- |
-
|
-
|
-
|
eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.
|
-
|
CVE-2024-46646
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319581
|
- |
-
|
-
|
-
|
eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
|
-
|
CVE-2024-46645
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319582
|
- |
-
|
-
|
-
|
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.
|
-
|
CVE-2024-46644
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319583
|
- |
-
|
-
|
-
|
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote…
|
-
|
CVE-2024-46640
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319584
|
- |
-
|
-
|
-
|
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
|
-
|
CVE-2024-46103
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319585
|
- |
-
|
-
|
-
|
GDidees CMS <= v3.9.1 has a file upload vulnerability.
|
-
|
CVE-2024-46101
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319586
|
- |
-
|
-
|
-
|
Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site scripting vulnerability: GET /v1/cr…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45793
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319587
|
- |
-
|
-
|
-
|
Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding pa…
|
CWE-89
SQL Injection
|
CVE-2024-47062
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319588
|
- |
-
|
-
|
-
|
Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM att…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47061
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319589
|
- |
-
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
-
|
CVE-2024-46654
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319590
|
- |
-
|
-
|
-
|
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the cont…
|
CWE-200
Information Exposure
|
CVE-2024-42351
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319591
|
- |
-
|
-
|
-
|
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations en…
|
CWE-79
Cross-site Scripting
|
CVE-2024-42346
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319592
|
- |
-
|
-
|
-
|
Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.
|
-
|
CVE-2024-42697
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319593
|
- |
-
|
-
|
-
|
The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. Howeve…
|
-
|
CVE-2024-45229
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319594
|
- |
-
|
-
|
-
|
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to cr…
|
-
|
CVE-2024-45489
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319595
|
- |
-
|
-
|
-
|
A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument tid leads to …
|
CWE-89
SQL Injection
|
CVE-2024-9037
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319596
|
- |
-
|
-
|
-
|
A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. The manipulation of the argument i…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-9036
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319597
|
- |
-
|
-
|
-
|
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.
|
-
|
CVE-2024-46652
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319598
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/login.php of the component Admin Login…
|
CWE-89
SQL Injection
|
CVE-2024-9035
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319599
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulatio…
|
CWE-89
SQL Injection
|
CVE-2024-9034
|
2024-09-26 22:32 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319600
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Check index for aux_rd_interval before using
aux_rd_interval has size of 7 and should be checked.
This fixes 3 …
|
NVD-CWE-noinfo
|
CVE-2024-46728
|
2024-09-26 22:31 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|