|
320151
|
9.8 |
CRITICAL
Network
|
stylemixthemes
|
cost_calculator_builder
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Bu…
|
CWE-89
SQL Injection
|
CVE-2024-43144
|
2024-09-20 06:47 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320152
|
9.8 |
CRITICAL
Network
|
templateinvaders
|
ti_woocommerce_wishlist
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce W…
|
CWE-89
SQL Injection
|
CVE-2024-43917
|
2024-09-20 06:46 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320153
|
9.8 |
CRITICAL
Network
|
nitropack
|
nitropack
|
Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.
|
CWE-94
Code Injection
|
CVE-2024-43922
|
2024-09-20 06:44 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320154
|
8.8 |
HIGH
Adjacent
|
dlink
|
covr-x1870_firmware dir-x4860_firmware
|
Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded…
|
CWE-912
Hidden Functionality
|
CVE-2024-45696
|
2024-09-20 06:42 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320155
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-x4860_firmware
|
Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS comm…
|
CWE-912
Hidden Functionality
|
CVE-2024-45697
|
2024-09-20 06:40 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320156
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluck
|
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2024-43042
|
2024-09-20 06:01 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320157
|
8.8 |
HIGH
Network
|
nuxt
|
nuxt
|
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an…
|
CWE-94
Code Injection
|
CVE-2024-34344
|
2024-09-20 05:58 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320158
|
7.5 |
HIGH
Network
|
nuxt
|
nuxt
|
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon lookup. This endpoint is at `/api/_nuxt_…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-42352
|
2024-09-20 05:55 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320159
|
7.8 |
HIGH
Local
|
mongodb
|
mongodb c_driver php_driver
|
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing…
|
NVD-CWE-noinfo
|
CVE-2024-7553
|
2024-09-20 05:46 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320160
|
6.1 |
MEDIUM
Network
|
mailcow
|
mailcow\
|
mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API l…
|
CWE-79
Cross-site Scripting
|
CVE-2024-41959
|
2024-09-20 05:14 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320161
|
4.8 |
MEDIUM
Network
|
mailcow
|
mailcow\
|
mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration. The injected payload is ex…
|
CWE-79
Cross-site Scripting
|
CVE-2024-41960
|
2024-09-20 05:01 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320162
|
6.1 |
MEDIUM
Network
|
nuxt
|
nuxt
|
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but does not correctly …
|
CWE-79
Cross-site Scripting
|
CVE-2024-34343
|
2024-09-20 04:57 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320163
|
6.5 |
MEDIUM
Network
|
lunary
|
lunary
|
An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the auth tokens issued by the 'invit…
|
NVD-CWE-Other
|
CVE-2024-6087
|
2024-09-20 04:32 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320164
|
3.9 |
LOW
Physics
|
redhat opensc_project
|
enterprise_linux opensc
|
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When …
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-45620
|
2024-09-20 04:21 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320165
|
6.5 |
MEDIUM
Network
|
eaton
|
foreseer_electrical_power_monitoring_system
|
The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the l…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2024-31416
|
2024-09-20 04:06 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320166
|
8.1 |
HIGH
Network
|
eaton
|
foreseer_electrical_power_monitoring_system
|
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-31415
|
2024-09-20 03:50 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320167
|
6.1 |
MEDIUM
Network
|
eaton
|
foreseer_electrical_power_monitoring_system
|
The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sa…
|
CWE-79
Cross-site Scripting
|
CVE-2024-31414
|
2024-09-20 03:48 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320168
|
8.1 |
HIGH
Network
|
lunary
|
lunary
|
A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up for and create pro…
|
CWE-352
Origin Validation Error
|
CVE-2024-6862
|
2024-09-20 03:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320169
|
6.5 |
MEDIUM
Network
|
lunary
|
lunary
|
An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access righ…
|
CWE-1220
Insufficient Granularity of Access Control
|
CVE-2024-6867
|
2024-09-20 03:28 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320170
|
9.8 |
CRITICAL
Network
|
arm
|
mbed_tls
|
An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in…
|
CWE-295
Improper Certificate Validation
|
CVE-2024-45159
|
2024-09-20 03:26 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320171
|
4.8 |
MEDIUM
Network
|
peepso
|
peepso
|
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7655
|
2024-09-20 03:20 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320172
|
4.8 |
MEDIUM
Network
|
peepso
|
peepso
|
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, …
|
CWE-79
Cross-site Scripting
|
CVE-2024-7618
|
2024-09-20 03:20 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320173
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: avoid using null object of framebuffer
Instead of using state->fb->obj[0] directly, get object from framebuffer
…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46694
|
2024-09-20 03:16 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320174
|
5.4 |
MEDIUM
Network
|
microfocus
|
netiq_access_manager
|
Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects NetIQ Access Manager before 5.0.4.1 and 5.1.
|
CWE-79
Cross-site Scripting
|
CVE-2024-4554
|
2024-09-20 03:15 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320175
|
7.1 |
HIGH
Local
|
stripe
|
stripe-cli
|
stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a man…
|
CWE-22
Path Traversal
|
CVE-2024-45401
|
2024-09-20 03:12 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320176
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
pktgen: use cpus_read_lock() in pg_net_init()
I have seen the WARN_ON(smp_processor_id() != cpu) firing
in pktgen_thread_worker()…
|
NVD-CWE-noinfo
|
CVE-2024-46681
|
2024-09-20 03:10 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320177
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
binfmt_elf_fdpic: fix AUXV size calculation when ELF_HWCAP2 is defined
create_elf_fdpic_tables() does not correctly account the s…
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2024-46684
|
2024-09-20 03:04 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320178
|
6.1 |
MEDIUM
Network
|
mlewand
|
open_link
|
ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new tab. A vulnerability in versions of the plugin pr…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45400
|
2024-09-20 03:04 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320179
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
erofs: fix out-of-bound access when z_erofs_gbuf_growsize() partially fails
If z_erofs_gbuf_growsize() partially fails on a globa…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-46688
|
2024-09-20 03:01 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320180
|
5.3 |
MEDIUM
Network
|
apple
|
visionos
|
The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard may be inferred from Persona.
|
NVD-CWE-noinfo
|
CVE-2024-40865
|
2024-09-20 02:58 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320181
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nfsd: ensure that nfsd4_fattr_args.context is zeroed out
If nfsd4_encode_fattr4 ends up doing a "goto out" before we get to
check…
|
CWE-665
Improper Initialization
|
CVE-2024-46697
|
2024-09-20 02:53 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320182
|
9.8 |
CRITICAL
Network
|
flycass
|
flycass
|
FlyCASS CASS and KCM systems did not correctly filter SQL queries, which
made them vulnerable to attack by outside attackers with no
authentication.
|
CWE-89
SQL Injection
|
CVE-2024-8395
|
2024-09-20 02:53 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320183
|
4.4 |
MEDIUM
Local
|
tcpdump
|
libpcap
|
In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the…
|
CWE-415
Double Free
|
CVE-2023-7256
|
2024-09-20 02:53 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320184
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tty: serial: fsl_lpuart: mark last busy before uart_add_one_port
With "earlycon initcall_debug=1 loglevel=8" in bootargs, kernel
…
|
NVD-CWE-noinfo
|
CVE-2024-46706
|
2024-09-20 02:51 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320185
|
4.4 |
MEDIUM
Local
|
tcpdump
|
libpcap
|
Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions that become available is pcap_findalldevs…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-8006
|
2024-09-20 02:46 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320186
|
4.9 |
MEDIUM
Network
|
jpress
|
jpress
|
A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/template/edit of the component Template …
|
CWE-22
Path Traversal
|
CVE-2024-8304
|
2024-09-20 02:39 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320187
|
6.5 |
MEDIUM
Network
|
openzeppelin
|
contracts
|
Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original owner's i…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2024-45304
|
2024-09-20 02:26 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320188
|
4.3 |
MEDIUM
Network
|
teamviewer
|
meeting teamviewer
|
Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the cl…
|
NVD-CWE-Other
|
CVE-2024-6053
|
2024-09-20 02:22 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320189
|
5.3 |
MEDIUM
Network
|
shedaniel
|
roughlyenoughitems
|
Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to validate slot index…
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-42698
|
2024-09-20 01:29 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320190
|
5.3 |
MEDIUM
Network
|
mezz
|
justenoughitems
|
JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to validate slot index in JE…
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-41565
|
2024-09-20 01:19 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320191
|
7.3 |
HIGH
Local
|
openpolicyagent
|
open_policy_agent
|
A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrar…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2024-8260
|
2024-09-20 01:08 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320192
|
4.6 |
MEDIUM
Physics
|
ibm
|
maas360_mdm
|
IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical access to the device.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-35118
|
2024-09-20 00:53 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320193
|
8.1 |
HIGH
Network
|
zohocorp
|
manageengine_exchange_reporter_plus
|
Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.
|
CWE-89
SQL Injection
|
CVE-2024-6204
|
2024-09-20 00:41 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320194
|
8.1 |
HIGH
Network
|
master-nan
|
sweet-cms
|
A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as problematic. This issue affects the function LogHandler of the file middleware/l…
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2024-8334
|
2024-09-20 00:39 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320195
|
9.8 |
CRITICAL
Network
|
openrapid
|
rapidcms
|
A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username …
|
CWE-89
SQL Injection
|
CVE-2024-8335
|
2024-09-20 00:31 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320196
|
8.1 |
HIGH
Network
|
eclipse
|
eclipse_dataspace_components
|
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date…
|
CWE-287
Improper Authentication
|
CVE-2024-8642
|
2024-09-20 00:18 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320197
|
7.5 |
HIGH
Network
|
hoverfly
|
hoverfly
|
Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new simulation views from …
|
CWE-22
Path Traversal
|
CVE-2024-45388
|
2024-09-20 00:18 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320198
|
4.6 |
MEDIUM
Physics
|
idec
|
kit-fc6a-24-kc_firmware kit-fc6a-24-pc_firmware kit-fc6a-24-ra_firmware kit-fc6a-24-ra-hg1g_firmware kit-fc6a-24-ra-hg2g-5tn_firmware kit-fc6a-24-ra-hg2g-5tt_firmware kit-fc6a-24-rc…
|
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtaine…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-41927
|
2024-09-20 00:10 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320199
|
7.8 |
HIGH
Local
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …
|
CWE-416
Use After Free
|
CVE-2024-41869
|
2024-09-20 00:09 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320200
|
7.5 |
HIGH
Network
|
fujitsu
|
ipcom_ve2_ls_100_firmware ipcom_ve2_ls_200_firmware ipcom_ve2_ls_220_firmware ipcom_ve2_ls_plus_100_firmware ipcom_ve2_ls_plus_200_firmware ipcom_ve2_ls_plus_220_firmware ipcom_ve2_…
|
Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-39921
|
2024-09-19 23:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|