|
320201
|
7.8 |
HIGH
Local
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context …
|
CWE-843
Type Confusion
|
CVE-2024-45112
|
2024-09-19 23:56 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320202
|
7.5 |
HIGH
Network
|
utarit
|
soliclub
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data.This issue affects SoliClub: before 4.4.0 for iOS, befo…
|
NVD-CWE-noinfo
|
CVE-2024-3305
|
2024-09-19 23:44 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320203
|
7.5 |
HIGH
Network
|
utarit
|
soliclub
|
Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SoliClub: befo…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-3306
|
2024-09-19 23:43 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320204
|
5.3 |
MEDIUM
Network
|
emilyploszaj
|
emi
|
EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to validate slot index and …
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-41564
|
2024-09-19 23:40 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320205
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_pam360 manageengine_password_manager_pro
|
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
|
CWE-89
SQL Injection
|
CVE-2024-5546
|
2024-09-19 23:39 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320206
|
5.4 |
MEDIUM
Network
|
connx
|
esp_hr_management
|
Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7269
|
2024-09-19 23:37 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320207
|
7.5 |
HIGH
Network
|
rockwellautomation
|
compactlogix_5380_firmware compact_guardlogix_5380_sil_2_firmware compact_guardlogix_5380_sil_3_firmware compactlogix_5480_firmware controllogix_5580_firmware guardlogix_5580_firmware<…
|
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailab…
|
NVD-CWE-noinfo
|
CVE-2024-6077
|
2024-09-19 23:31 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320208
|
9.8 |
CRITICAL
Network
|
soplanning
|
soplanning
|
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be avai…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2024-27114
|
2024-09-19 23:27 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320209
|
6.1 |
MEDIUM
Network
|
microfocus
|
edirectory
|
Possible
Improper Neutralization of Input During Web Page Generation Vulnerability
in eDirectory has been discovered in
OpenText™ eDirectory 9.2.3.0000.
|
CWE-79
Cross-site Scripting
|
CVE-2021-22503
|
2024-09-19 23:25 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320210
|
9.1 |
CRITICAL
Network
|
microfocus
|
edirectory
|
Possible Insertion of Sensitive Information into Log File Vulnerability
in eDirectory has been discovered in
OpenText™ eDirectory 9.2.4.0000.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-22533
|
2024-09-19 23:24 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320211
|
7.5 |
HIGH
Network
|
microfocus
|
edirectory
|
Possible NLDAP Denial of Service attack Vulnerability
in eDirectory has been discovered in
OpenText™
eDirectory before 9.2.4.0000.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-22532
|
2024-09-19 23:22 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320212
|
7.5 |
HIGH
Network
|
cisco
|
smart_license_utility
|
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.
This vulnerability is due to excessive verbosity in a debug log fi…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-20440
|
2024-09-19 22:42 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320213
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
libfs: fix infinite directory reads for offset dir
After we switch tmpfs dir operations from simple_dir_operations to
simple_offs…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2024-46701
|
2024-09-19 22:40 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320214
|
5.4 |
MEDIUM
Network
|
share_this_image_project
|
share_this_image
|
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 due to insufficient input sanitization …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8108
|
2024-09-19 22:37 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320215
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Mark XDomain as unplugged when router is removed
I noticed that when we do discrete host router NVM upgrade and it g…
|
NVD-CWE-noinfo
|
CVE-2024-46702
|
2024-09-19 22:35 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320216
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
Revert "serial: 8250_omap: Set the console genpd always on if no console suspend"
This reverts commit 68e6939ea9ec3d6579eadeab160…
|
NVD-CWE-noinfo
|
CVE-2024-46703
|
2024-09-19 22:33 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320217
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
workqueue: Fix spruious data race in __flush_work()
When flushing a work item for cancellation, __flush_work() knows that it
excl…
|
NVD-CWE-noinfo
|
CVE-2024-46704
|
2024-09-19 22:32 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320218
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: reset mmio mappings with devm
Set our various mmio mappings to NULL. This should make it easier to
catch something rogue …
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46705
|
2024-09-19 22:30 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320219
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3
On a system with a GICv3, if a guest hasn't been configured with
…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46707
|
2024-09-19 22:29 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320220
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: qcom: x1e80100: Fix special pin offsets
Remove the erroneus 0x100000 offset to prevent the boards from crashing
on pin s…
|
NVD-CWE-noinfo
|
CVE-2024-46708
|
2024-09-19 22:28 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320221
|
5.3 |
MEDIUM
Network
|
miniorange
|
web_application_firewall
|
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address inform…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2022-4539
|
2024-09-19 22:27 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320222
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Fix prime with external buffers
Make sure that for external buffers mapping goes through the dma_buf
interface instea…
|
NVD-CWE-noinfo
|
CVE-2024-46709
|
2024-09-19 22:26 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320223
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix ID 0 endp usage after multiple re-creations
'local_addr_used' and 'add_addr_accepted' are decremented for addresse…
|
NVD-CWE-noinfo
|
CVE-2024-46711
|
2024-09-19 22:12 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320224
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Disable coherent dumb buffers without 3d
Coherent surfaces make only sense if the host renders to them using
accelera…
|
NVD-CWE-noinfo
|
CVE-2024-46712
|
2024-09-19 22:09 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320225
|
9.8 |
CRITICAL
Network
|
tnbmobil
|
cockpit
|
Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable.This issue affects Cockpit Software: before v2.13.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-6656
|
2024-09-19 22:05 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320226
|
5.3 |
MEDIUM
Network
|
secreto31126
|
whatsapp-api-js
|
whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the…
|
NVD-CWE-Other
|
CVE-2024-45607
|
2024-09-19 11:05 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320227
|
8.8 |
HIGH
Network
|
rockwellautomation
|
2800c_optixpanel_compact_firmware 2800s_optixpanel_standard_firmware embedded_edge_compute_module_firmware
|
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials an…
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-8533
|
2024-09-19 10:57 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320228
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
pavilion8
|
A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execut…
|
CWE-22
Path Traversal
|
CVE-2024-7961
|
2024-09-19 10:52 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320229
|
9.1 |
CRITICAL
Network
|
rockwellautomation
|
pavilion8
|
The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect pri…
|
NVD-CWE-noinfo
|
CVE-2024-7960
|
2024-09-19 10:52 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320230
|
4.3 |
MEDIUM
Network
|
lenovo
|
xclarity_administrator
|
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
|
NVD-CWE-noinfo
|
CVE-2024-45103
|
2024-09-19 10:50 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320231
|
6.5 |
MEDIUM
Network
|
lenovo
|
xclarity_administrator
|
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
|
NVD-CWE-noinfo
|
CVE-2024-45104
|
2024-09-19 10:49 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320232
|
9.8 |
CRITICAL
Network
|
heyewei
|
jfinalcms
|
A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. The manipulation of the argument name leads t…
|
CWE-22
Path Traversal
|
CVE-2024-8782
|
2024-09-19 10:46 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320233
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: Encryption procedure host vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-5754
|
2024-09-19 10:44 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320234
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: Missing length checks of net_buf in rfcomm_handle_data
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2024-6258
|
2024-09-19 10:40 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320235
|
9.8 |
CRITICAL
Network
|
mayurik
|
best_free_law_office_management
|
SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/con…
|
CWE-89
SQL Injection
|
CVE-2024-44430
|
2024-09-19 10:38 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320236
|
8.8 |
HIGH
Network
|
qdocs
|
smart_school
|
A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnerability is an unknown functionality of the file /user/chat/mynewuser of the comp…
|
CWE-89
SQL Injection
|
CVE-2024-8784
|
2024-09-19 10:38 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320237
|
5.4 |
MEDIUM
Network
|
opentibiabr
|
myaac
|
A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown function of the file system/pages/forum/new_post.php of the component Post Reply Han…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8783
|
2024-09-19 10:38 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320238
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: Unchecked user input in bap_broadcast_assistant
|
CWE-787
Out-of-bounds Write
|
CVE-2024-5931
|
2024-09-19 10:35 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320239
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT:Classic: Multiple missing buf length checks
|
CWE-369
Divide By Zero
|
CVE-2024-6135
|
2024-09-19 10:34 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320240
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: HCI: adv_ext_report Improper discarding in adv_ext_report
|
CWE-787
Out-of-bounds Write
|
CVE-2024-6259
|
2024-09-19 10:33 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320241
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: Classic: SDP OOB access in get_att_search_list
|
CWE-787
Out-of-bounds Write
|
CVE-2024-6137
|
2024-09-19 10:33 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320242
|
6.5 |
MEDIUM
Network
|
microfocus
|
edirectory
|
Possible
External Service Interaction attack
in eDirectory has been discovered in
OpenText™ eDirectory. This impact all version before 9.2.6.0000.
|
CWE-521
Weak Password Requirements
|
CVE-2021-38133
|
2024-09-19 06:05 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320243
|
9.8 |
CRITICAL
Network
|
microfocus
|
edirectory
|
Possible
External Service Interaction attack
in eDirectory has been discovered in
OpenText™ eDirectory. This impact all version before 9.2.6.0000.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-38132
|
2024-09-19 06:04 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320244
|
6.1 |
MEDIUM
Network
|
microfocus
|
edirectory
|
Possible Cross-Site Scripting (XSS) Vulnerability
in eDirectory has been discovered in
OpenText™ eDirectory 9.2.5.0000.
|
CWE-79
Cross-site Scripting
|
CVE-2021-38131
|
2024-09-19 06:00 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320245
|
6.1 |
MEDIUM
Network
|
i-doit
|
i-doit
|
Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8750
|
2024-09-19 05:38 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320246
|
5.3 |
MEDIUM
Network
|
ordat
|
ordat.erp
|
User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password func…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-34336
|
2024-09-19 05:32 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320247
|
6.1 |
MEDIUM
Network
|
ordat
|
ordat.erp
|
ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.
|
CWE-79
Cross-site Scripting
|
CVE-2024-34335
|
2024-09-19 05:32 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320248
|
7.5 |
HIGH
Network
|
ordat
|
ordat.erp
|
ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.
|
CWE-89
SQL Injection
|
CVE-2024-34334
|
2024-09-19 05:32 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320249
|
9.8 |
CRITICAL
Network
|
soplanning
|
soplanning
|
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publ…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-27115
|
2024-09-19 05:32 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320250
|
3.1 |
LOW
Network
|
keyfactor
|
ejbca
|
The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFC 4211, and might make man-in-the-middle attacks easier. CM…
|
NVD-CWE-noinfo
|
CVE-2024-36066
|
2024-09-19 05:28 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|