|
319651
|
9.8 |
CRITICAL
Network
|
gematik
|
reference_validator
|
The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile location routine in the referencevalidator commons p…
|
CWE-611
XXE
|
CVE-2024-46984
|
2024-09-26 02:49 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319652
|
9.8 |
CRITICAL
Network
|
code-projects
|
crud_operation_system
|
A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0. Affected is an unknown function of the file updata.php. The manipulation of the argument sid l…
|
CWE-89
SQL Injection
|
CVE-2024-9011
|
2024-09-26 02:48 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319653
|
9.8 |
CRITICAL
Network
|
fabianros
|
online_quiz_site
|
A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0. This issue affects some unknown processing of the file showtest.php. The manipulation of the a…
|
CWE-89
SQL Injection
|
CVE-2024-9009
|
2024-09-26 02:46 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319654
|
9.8 |
CRITICAL
Network
|
antfin
|
sofa-hessian
|
sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous cla…
|
NVD-CWE-noinfo
|
CVE-2024-46983
|
2024-09-26 02:46 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319655
|
7.5 |
HIGH
Network
|
traefik
|
traefik
|
Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the req…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2024-45410
|
2024-09-26 02:39 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319656
|
9.8 |
CRITICAL
Network
|
d7y
|
dragonfly
|
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2023-27584
|
2024-09-26 02:28 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319657
|
6.5 |
MEDIUM
Network
|
envoyproxy
|
envoy
|
Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2024-45808
|
2024-09-26 02:18 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319658
|
5.3 |
MEDIUM
Network
|
jflow_project
|
jflow
|
A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.…
|
NVD-CWE-Other
|
CVE-2024-9003
|
2024-09-26 02:18 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319659
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management in the codec. To …
|
NVD-CWE-noinfo
|
CVE-2024-45807
|
2024-09-26 02:12 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319660
|
5.4 |
MEDIUM
Network
|
cryoutcreations
|
kahuna
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Kahuna allows Stored XSS.This issue affects Kahuna: from n/a through 1.7.0.
|
CWE-79
Cross-site Scripting
|
CVE-2024-43994
|
2024-09-26 02:09 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319661
|
7.5 |
HIGH
Network
|
trianglemicroworks siemens
|
iec_61850_source_code_library sicam_a8000_firmware sicam_scc_firmware sicam_egs_firmware sicam_s8000 sitipe_at
|
Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in …
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-34057
|
2024-09-26 02:08 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319662
|
8.8 |
HIGH
Network
|
frogcms_project
|
frogcms
|
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123
|
CWE-352
Origin Validation Error
|
CVE-2024-46086
|
2024-09-26 02:08 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319663
|
7.5 |
HIGH
Network
|
quinn_project
|
quinn
|
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, `refuse()`, or `ignore()` an `…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2024-45311
|
2024-09-26 02:03 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319664
|
7.5 |
HIGH
Network
|
linlinjava
|
litemall
|
A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminGoodscontroller.java.
|
CWE-89
SQL Injection
|
CVE-2024-46382
|
2024-09-26 01:56 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319665
|
8.8 |
HIGH
Network
|
frogcms_project
|
frogcms
|
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
|
CWE-352
Origin Validation Error
|
CVE-2024-46394
|
2024-09-26 01:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319666
|
7.3 |
HIGH
Local
|
pixlone
|
logiops
|
logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, including setting malicious keyboard macros. This al…
|
NVD-CWE-noinfo
|
CVE-2024-45752
|
2024-09-26 01:54 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319667
|
5.4 |
MEDIUM
Network
|
workdo
|
crmgo_saas
|
A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affects some unknown processing of the file /project/task/{task_id}/show. The manip…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9031
|
2024-09-26 01:52 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319668
|
3.3 |
LOW
Local
|
apple
|
macos
|
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15. A malicious app may be able to access notifications from the user's device.
|
NVD-CWE-noinfo
|
CVE-2024-40838
|
2024-09-26 01:46 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319669
|
6.5 |
MEDIUM
Network
|
zitadel
|
zitadel
|
Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across other o…
|
CWE-863
Incorrect Authorization
|
CVE-2024-47060
|
2024-09-26 01:43 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319670
|
- |
-
|
-
|
-
|
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A rogue administrator could add a malicious payload by executing it in the browse…
|
-
|
CVE-2024-8661
|
2024-09-26 01:15 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319671
|
- |
-
|
-
|
-
|
In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocati…
|
-
|
CVE-2024-7625
|
2024-09-26 01:15 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319672
|
4.8 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a thro…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43999
|
2024-09-26 00:15 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319673
|
6.5 |
MEDIUM
Adjacent
|
apple
|
iphone_os ipados
|
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A malicious Bluetooth input device may bypass pairing.
|
NVD-CWE-noinfo
|
CVE-2024-44124
|
2024-09-26 00:14 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319674
|
5.4 |
MEDIUM
Network
|
webhammer
|
wp_custom_fields_search
|
The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-preset shortcode in all versions up to, and including, 1.2.35 due to insufficient …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8364
|
2024-09-26 00:08 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319675
|
9.8 |
CRITICAL
Network
|
freeimage_project
|
freeimage
|
libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-31570
|
2024-09-25 23:57 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319676
|
9.8 |
CRITICAL
Network
|
spx
|
spx_graphics_controller
|
An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.
|
CWE-94
Code Injection
|
CVE-2024-44623
|
2024-09-25 23:53 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319677
|
9.8 |
CRITICAL
Network
|
ergophone yealink
|
tiptel_ip_286_firmware sip-t28p_firmware
|
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
|
CWE-22
Path Traversal
|
CVE-2024-33109
|
2024-09-25 23:47 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319678
|
9.8 |
CRITICAL
Network
|
closed-loop
|
cless_server
|
An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the u…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-40125
|
2024-09-25 23:46 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319679
|
6.1 |
MEDIUM
Network
|
surecart
|
surecart
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SureCart allows Reflected XSS.This issue affects SureCart: from n/a through 2.29.3.
|
CWE-79
Cross-site Scripting
|
CVE-2024-43970
|
2024-09-25 23:18 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319680
|
4.8 |
MEDIUM
Network
|
pagelayer
|
pagelayer
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pagelayer Team PageLayer allows Stored XSS.This issue affects PageLayer: from n/a through …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43972
|
2024-09-25 23:16 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319681
|
5.4 |
MEDIUM
Network
|
podlove
|
podlove_podcast_publisher
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Stored XSS.This issue affects Podlove Podcast Pub…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43983
|
2024-09-25 23:11 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319682
|
5.4 |
MEDIUM
Network
|
wayneconnor
|
sliding_door
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wayneconnor Sliding Door allows Stored XSS.This issue affects Sliding Door: from n/a throu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43987
|
2024-09-25 23:08 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319683
|
5.4 |
MEDIUM
Network
|
digitalnature
|
mystique
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in digitalnature Mystique allows Stored XSS.This issue affects Mystique: from n/a through 2.5…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43988
|
2024-09-25 22:55 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319684
|
5.4 |
MEDIUM
Network
|
webdzier
|
hotel_galaxy
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webdzier Hotel Galaxy allows Stored XSS.This issue affects Hotel Galaxy: from n/a through …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43991
|
2024-09-25 22:53 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319685
|
5.4 |
MEDIUM
Network
|
latepoint
|
latepoint
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Latepoint LatePoint allows Stored XSS.This issue affects LatePoint: from n/a through 4.9.9…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43992
|
2024-09-25 22:47 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319686
|
5.4 |
MEDIUM
Network
|
cryoutcreations
|
liquido
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Liquido allows Stored XSS.This issue affects Liquido: from n/a through 1.0…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43993
|
2024-09-25 22:44 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319687
|
7.5 |
HIGH
Network
|
apple
|
macos iphone_os ipados
|
An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, tvOS 18, macOS Sequoia 15. An attacker may be able to force a device to disconnect from a secure …
|
NVD-CWE-noinfo
|
CVE-2024-40856
|
2024-09-25 22:43 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319688
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of the file system.
|
NVD-CWE-noinfo
|
CVE-2024-40860
|
2024-09-25 22:41 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319689
|
6.1 |
MEDIUM
Network
|
apple
|
macos iphone_os ipados visionos watchos tvos safari
|
This issue was addressed through improved state management. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted w…
|
CWE-79
Cross-site Scripting
|
CVE-2024-40857
|
2024-09-25 22:41 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319690
|
5.5 |
MEDIUM
Local
|
apple
|
iphone_os ipados
|
This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to leak sensitive user information.
|
NVD-CWE-noinfo
|
CVE-2024-40863
|
2024-09-25 22:40 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319691
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. A malicious application may be able to leak sensitive user information.
|
NVD-CWE-noinfo
|
CVE-2024-44125
|
2024-09-25 22:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319692
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An Automator Quick Action workflow may be abl…
|
NVD-CWE-noinfo
|
CVE-2024-44128
|
2024-09-25 22:29 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319693
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access protected files within an App Sandbox containe…
|
NVD-CWE-noinfo
|
CVE-2024-44135
|
2024-09-25 22:28 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319694
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, macOS Sequoia 15. An app may be able to leak sensitive user information.
|
NVD-CWE-noinfo
|
CVE-2024-44129
|
2024-09-25 22:28 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319695
|
5.5 |
MEDIUM
Local
|
apple
|
macos ipados iphone_os visionos watchos tvos
|
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iP…
|
NVD-CWE-noinfo
|
CVE-2024-44176
|
2024-09-25 22:27 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319696
|
6.5 |
MEDIUM
Network
|
apple
|
macos iphone_os ipados visionos watchos tvos safari
|
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 …
|
CWE-346
Origin Validation Error
|
CVE-2024-44187
|
2024-09-25 22:25 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319697
|
5.5 |
MEDIUM
Local
|
apple
|
macos ipados iphone_os visionos watchos tvos xcode
|
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, Xcode 16, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. An app …
|
NVD-CWE-noinfo
|
CVE-2024-44191
|
2024-09-25 22:24 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319698
|
- |
-
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2143 Reason: This candidate is a reservation duplicate of CVE-2023-2143. Notes: All CVE users should reference
CV…
|
-
|
CVE-2024-9063
|
2024-09-25 10:15 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319699
|
- |
-
|
-
|
-
|
A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD tra…
|
CWE-295
Improper Certificate Validation
|
CVE-2024-7383
|
2024-09-25 10:15 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319700
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
Calculating the size of the mapped area as the lesser value
betwe…
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2024-42259
|
2024-09-25 10:15 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|