|
319601
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/pm: fix the Out-of-bounds read warning
using index i - 1U may beyond element index
for mc_data[] when i = 0.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-46731
|
2024-09-26 22:29 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319602
|
5.4 |
MEDIUM
Network
|
puma
|
puma
|
Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing a underscore version of the …
|
CWE-444
HTTP Request Smuggling
|
CVE-2024-45614
|
2024-09-26 22:28 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319603
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Assign linear_pitch_alignment even for VM
[Description]
Assign linear_pitch_alignment so we don't cause a divide…
|
CWE-369
Divide By Zero
|
CVE-2024-46732
|
2024-09-26 22:28 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319604
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
mwifiex_get_priv_by_id() returns the priv pointer correspond…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46755
|
2024-09-26 22:25 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319605
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ice: protect XDP configuration with a mutex
The main threat to data consistency in ice_xdp() is a possible asynchronous
PF reset.…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46765
|
2024-09-26 22:24 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319606
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup
Currently napi_disable() gets called during rxq and txq clean…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-46784
|
2024-09-26 22:21 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319607
|
- |
-
|
-
|
-
|
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived chan…
|
-
|
CVE-2024-47145
|
2024-09-26 17:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319608
|
- |
-
|
-
|
-
|
Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a pe…
|
-
|
CVE-2024-47003
|
2024-09-26 17:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319609
|
- |
-
|
-
|
-
|
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deploy…
|
-
|
CVE-2024-45843
|
2024-09-26 17:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319610
|
- |
-
|
-
|
-
|
User interface (UI) misrepresentation of critical information issue exists in multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION. If this vulnerabi…
|
-
|
CVE-2024-47045
|
2024-09-26 13:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319611
|
- |
-
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-22303
|
2024-09-26 12:15 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319612
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_10_1507
|
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released Ju…
|
NVD-CWE-noinfo
|
CVE-2024-43491
|
2024-09-26 10:00 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319613
|
- |
-
|
-
|
-
|
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: It is a duplicate of CVE-2010-2799.
|
-
|
CVE-2010-10005
|
2024-09-26 08:15 |
2023-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319614
|
- |
-
|
-
|
-
|
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafte…
|
-
|
CVE-2024-41433
|
2024-09-26 06:15 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319615
|
- |
-
|
-
|
-
|
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnne…
|
-
|
CVE-2024-41434
|
2024-09-26 06:15 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319616
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortianalyzer fortimanager fortianalyzer-bigdata
|
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2023-44254
|
2024-09-26 05:17 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319617
|
5.4 |
MEDIUM
Network
|
sktthemes
|
posterity
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sonalsinha21 Posterity allows Stored XSS.This issue affects Posterity: from n/a through 3.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43995
|
2024-09-26 05:01 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319618
|
8.8 |
HIGH
Network
|
microsoft
|
groupme
|
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.
|
NVD-CWE-noinfo
|
CVE-2024-38183
|
2024-09-26 04:59 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319619
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a …
|
CWE-601
Open Redirect
|
CVE-2024-8897
|
2024-09-26 04:49 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319620
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15. Privacy Indicators for microphone or camera access may be attributed incorrectly.
|
NVD-CWE-noinfo
|
CVE-2024-27875
|
2024-09-26 04:44 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319621
|
4.6 |
MEDIUM
Physics
|
apple
|
iphone_os ipados
|
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data.
|
NVD-CWE-noinfo
|
CVE-2024-40840
|
2024-09-26 04:42 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319622
|
8.8 |
HIGH
Network
|
pickplugins
|
post_grid
|
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta value…
|
NVD-CWE-noinfo
|
CVE-2024-8253
|
2024-09-26 04:42 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319623
|
4.8 |
MEDIUM
Network
|
enviragallery
|
envira_gallery
|
The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform…
|
CWE-79
Cross-site Scripting
|
CVE-2024-3899
|
2024-09-26 04:37 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319624
|
4.8 |
MEDIUM
Network
|
gsplugins
|
gs_logo_slider
|
The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks e…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7716
|
2024-09-26 04:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319625
|
5.4 |
MEDIUM
Network
|
wpdeveloper
|
essential_addons_for_elementor
|
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widge…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8440
|
2024-09-26 04:34 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319626
|
8.1 |
HIGH
Network
|
wpdelicious
|
wp_delicious
|
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to insufficient file path validation in t…
|
NVD-CWE-Other
|
CVE-2024-7626
|
2024-09-26 04:32 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319627
|
8.8 |
HIGH
Network
|
fairsketch
|
rise_ultimate_project_manager
|
A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboard/save. The manipul…
|
CWE-89
SQL Injection
|
CVE-2024-8945
|
2024-09-26 04:24 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319628
|
4.3 |
MEDIUM
Network
|
contao
|
contao
|
Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13…
|
CWE-22
Path Traversal
|
CVE-2024-45604
|
2024-09-26 04:22 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319629
|
5.4 |
MEDIUM
Network
|
wpbackgrounds
|
advanced_wordpress_backgrounds
|
The Advanced WordPress Backgrounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘imageTag’ parameter in all versions up to, and including, 1.12.3 due to insufficient inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8045
|
2024-09-26 04:22 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319630
|
8.8 |
HIGH
Network
|
contao
|
contao
|
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.1…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-45398
|
2024-09-26 04:20 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319631
|
4.8 |
MEDIUM
Network
|
eladmin
|
eladmin
|
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44676
|
2024-09-26 04:20 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319632
|
9.8 |
CRITICAL
Network
|
eladmin
|
eladmin
|
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-44677
|
2024-09-26 04:19 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319633
|
8.8 |
HIGH
Network
|
microsoft
|
dynamics_365_business_central
|
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
|
NVD-CWE-noinfo
|
CVE-2024-43460
|
2024-09-26 04:18 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319634
|
4.6 |
MEDIUM
Physics
|
hathway
|
skyworth_cm5100-511_firmware
|
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-44815
|
2024-09-26 04:17 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319635
|
8.8 |
HIGH
Network
|
hfo4
|
shudong-share
|
A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /includes/fileReceive.php of the compon…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8338
|
2024-09-26 04:12 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319636
|
5.3 |
MEDIUM
Network
|
getastra
|
wp_hardening
|
The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular ex…
|
CWE-697
Incorrect Comparison
|
CVE-2024-6641
|
2024-09-26 04:07 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319637
|
6.1 |
MEDIUM
Network
|
svelte
|
svelte
|
svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The as…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45047
|
2024-09-26 04:06 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319638
|
6.1 |
MEDIUM
Network
|
elizsoftware
|
panel
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.
|
CWE-79
Cross-site Scripting
|
CVE-2024-6877
|
2024-09-26 03:57 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319639
|
9.8 |
CRITICAL
Network
|
elizsoftware
|
panel
|
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.
|
CWE-256
Plaintext Storage of a Password
|
CVE-2024-5960
|
2024-09-26 03:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319640
|
5.3 |
MEDIUM
Network
|
felixmoira
|
limit_login_attempts_plus
|
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address infor…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2022-4533
|
2024-09-26 03:53 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319641
|
6.1 |
MEDIUM
Network
|
ibericode
|
mailchimp
|
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8850
|
2024-09-26 03:49 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319642
|
8.8 |
HIGH
Network
|
jeanmarc77
|
123solar
|
A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file config/config_invt1.php. The manipulation of …
|
CWE-94
Code Injection
|
CVE-2024-9006
|
2024-09-26 03:44 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319643
|
5.4 |
MEDIUM
Network
|
jeanmarc77
|
123solar
|
A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9007
|
2024-09-26 03:40 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319644
|
5.3 |
MEDIUM
Network
|
overleaf
|
overleaf
|
Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a vulnerability that allows an arbitrary lan…
|
CWE-74
Injection
|
CVE-2024-45312
|
2024-09-26 03:37 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319645
|
6.0 |
MEDIUM
Network
|
fortinet
|
forticlient_endpoint_management_server
|
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.…
|
CWE-22
Path Traversal
|
CVE-2024-21753
|
2024-09-26 03:36 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319646
|
5.4 |
MEDIUM
Network
|
overleaf
|
overleaf
|
Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-compose.yml from before 2024-08-28, the configuration…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2024-45313
|
2024-09-26 03:12 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319647
|
6.5 |
MEDIUM
Network
|
opendaylight
|
model-driven_service_abstraction_layer
|
In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.
|
NVD-CWE-noinfo
|
CVE-2024-46942
|
2024-09-26 03:08 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319648
|
5.4 |
MEDIUM
Network
|
workdo
|
crmgo_saas
|
A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown code of the file /deal/{note_id}/note. The manipulation of the argument notes lead…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9030
|
2024-09-26 03:01 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319649
|
9.8 |
CRITICAL
Network
|
cellopoint
|
secure_email_gateway
|
Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated attackers can send crafted packets to crash the process, thereby bypassing aut…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-9043
|
2024-09-26 02:54 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319650
|
9.8 |
CRITICAL
Network
|
medialibs
|
webo-facto
|
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it…
|
NVD-CWE-noinfo
|
CVE-2024-8853
|
2024-09-26 02:49 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|