|
319951
|
- |
-
|
-
|
-
|
runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via the rtsp:// protocol to receive the video and audi…
|
-
|
CVE-2024-46959
|
2024-09-20 23:35 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319952
|
- |
-
|
-
|
-
|
An issue was discovered in Bravura Security Fabric versions 12.3.x before 12.3.5.32784, 12.4.x before 12.4.3.35110, 12.5.x before 12.5.2.35950, 12.6.x before 12.6.2.37183, and 12.7.x before 12.7.1.38…
|
-
|
CVE-2024-45523
|
2024-09-20 23:35 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319953
|
- |
-
|
-
|
-
|
Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.
|
-
|
CVE-2023-41612
|
2024-09-20 23:35 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319954
|
6.5 |
MEDIUM
Network
|
syscomgo
|
omflow
|
OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privileges to obtain accounts and password hashes of ot…
|
NVD-CWE-noinfo
|
CVE-2024-8780
|
2024-09-20 23:35 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319955
|
6.5 |
MEDIUM
Network
|
syscomgo
|
omflow
|
OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system files.
|
CWE-22
Path Traversal
|
CVE-2024-8778
|
2024-09-20 23:23 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319956
|
7.5 |
HIGH
Network
|
syscomgo
|
omflow
|
OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers can…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-8777
|
2024-09-20 23:22 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319957
|
6.5 |
MEDIUM
Network
|
ibm
|
aspera_shares
|
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
|
CWE-613
Insufficient Session Expiration
|
CVE-2024-38315
|
2024-09-20 23:09 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319958
|
7.8 |
HIGH
Local
|
mattermost
|
mattermost_desktop
|
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-39613
|
2024-09-20 22:59 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319959
|
5.3 |
MEDIUM
Physics
|
rfideas
|
micard_plus_ci_firmware micard_plus_ble_firmware
|
The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result in characters randomly being dropped from some ID card read…
|
NVD-CWE-noinfo
|
CVE-2024-1578
|
2024-09-20 22:53 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319960
|
6.1 |
MEDIUM
Network
|
jetbrains
|
intellij_idea
|
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
|
CWE-79
Cross-site Scripting
|
CVE-2024-46970
|
2024-09-20 22:23 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319961
|
5.0 |
MEDIUM
Network
|
nozominetworks
|
cmc guardian
|
An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges.
If a logged-in user with r…
|
CWE-863
Incorrect Authorization
|
CVE-2024-4465
|
2024-09-20 22:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319962
|
5.5 |
MEDIUM
Local
|
samsung
|
exynos_980_firmware exynos_850_firmware exynos_1080_firmware exynos_1280_firmware exynos_1380_firmware exynos_1330_firmware exynos_1480_firmware exynos_w920_firmware exynos_w9…
|
An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_b…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-27365
|
2024-09-20 22:09 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319963
|
7.2 |
HIGH
Network
|
mailcow
|
mailcow\
|
mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated at…
|
NVD-CWE-noinfo
|
CVE-2024-41958
|
2024-09-20 21:58 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319964
|
8.8 |
HIGH
Network
|
nuxt
|
nuxt
|
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vul…
|
CWE-22
Path Traversal
|
CVE-2024-23657
|
2024-09-20 21:49 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319965
|
- |
-
|
-
|
-
|
A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via th…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-5998
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319966
|
- |
-
|
-
|
-
|
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Back…
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2024-8767
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319967
|
- |
-
|
-
|
-
|
Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer.
If a computer on which the affected product is installed receives a large number of UDP broadcast packets…
|
-
|
CVE-2024-8110
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319968
|
- |
-
|
-
|
-
|
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone cont…
|
CWE-269
Improper Privilege Management
|
CVE-2024-45496
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319969
|
- |
-
|
-
|
-
|
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.
|
-
|
CVE-2024-44202
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319970
|
- |
-
|
-
|
-
|
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, macOS Sonom…
|
-
|
CVE-2024-44169
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319971
|
- |
-
|
-
|
-
|
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to overw…
|
-
|
CVE-2024-44167
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319972
|
- |
-
|
-
|
-
|
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted texture may lead …
|
-
|
CVE-2024-44160
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319973
|
- |
-
|
-
|
-
|
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local Network.
|
-
|
CVE-2024-44147
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319974
|
- |
-
|
-
|
-
|
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.
|
-
|
CVE-2024-44132
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319975
|
- |
-
|
-
|
-
|
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.
|
-
|
CVE-2024-44127
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319976
|
- |
-
|
-
|
-
|
A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of the computer.
|
-
|
CVE-2024-40862
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319977
|
- |
-
|
-
|
-
|
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root privileges.
|
-
|
CVE-2024-40861
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319978
|
- |
-
|
-
|
-
|
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assisti…
|
-
|
CVE-2024-40852
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319979
|
- |
-
|
-
|
-
|
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted video file may lead to unexpecte…
|
-
|
CVE-2024-40841
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319980
|
- |
-
|
-
|
-
|
The issue was addressed with improved checks. This issue is fixed in visionOS 2, macOS Sequoia 15. A malicious app with root privileges may be able to modify the contents of system files.
|
-
|
CVE-2024-40825
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319981
|
- |
-
|
-
|
-
|
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. An attacker may be able to cause unexpected app termination.
|
-
|
CVE-2024-27879
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319982
|
- |
-
|
-
|
-
|
A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. Unpac…
|
-
|
CVE-2024-27876
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319983
|
- |
-
|
-
|
-
|
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to cause a denial-of-service.
|
-
|
CVE-2024-27874
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319984
|
- |
-
|
-
|
-
|
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to record the screen without an indicator.
|
-
|
CVE-2024-27869
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319985
|
- |
-
|
-
|
-
|
The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates…
|
-
|
CVE-2024-45416
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319986
|
- |
-
|
-
|
-
|
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post req…
|
-
|
CVE-2024-45415
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319987
|
- |
-
|
-
|
-
|
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encry…
|
-
|
CVE-2024-45414
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319988
|
- |
-
|
-
|
-
|
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, the decr…
|
-
|
CVE-2024-45413
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319989
|
- |
-
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-8766
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319990
|
- |
-
|
-
|
-
|
Snappymail is an open source web-based email client. SnappyMail uses the `cleanHtml()` function to cleanup HTML and CSS in emails. Research discovered that the function has a few bugs which cause an …
|
CWE-79
Cross-site Scripting
|
CVE-2024-45800
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319991
|
- |
-
|
-
|
-
|
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged atta…
|
-
|
CVE-2024-42798
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319992
|
- |
-
|
-
|
-
|
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete t…
|
-
|
CVE-2024-42796
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319993
|
- |
-
|
-
|
-
|
An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an …
|
-
|
CVE-2024-42795
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319994
|
- |
-
|
-
|
-
|
Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.
|
-
|
CVE-2024-42794
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319995
|
- |
-
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-34016
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319996
|
- |
-
|
-
|
-
|
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking ad…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2024-45801
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319997
|
- |
-
|
-
|
-
|
FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/buyers list pages and shop names, that are currently not sanitized. This allows …
|
-
|
CVE-2024-45799
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319998
|
- |
-
|
-
|
-
|
A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in the add-to-cart function.
|
-
|
CVE-2023-45854
|
2024-09-20 21:31 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319999
|
- |
-
|
-
|
-
|
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code…
|
-
|
CVE-2024-7737
|
2024-09-20 21:30 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320000
|
- |
-
|
-
|
-
|
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execu…
|
-
|
CVE-2024-7736
|
2024-09-20 21:30 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|