111
|
3.3 |
LOW
Local
|
apple
|
ipados iphone_os macos
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to read sensitive location …
Update
|
NVD-CWE-noinfo
|
CVE-2023-40439
|
2024-11-7 05:35 |
2024-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
112
|
6.1 |
MEDIUM
Network
|
ahmetimamoglu
|
ahmeti_wp_timeline
|
Cross-Site Request Forgery (CSRF) vulnerability in Ahmet Imamoglu Ahmeti Wp Timeline allows Stored XSS.This issue affects Ahmeti Wp Timeline: from n/a through 5.1.
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-49237
|
2024-11-7 05:33 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
113
|
- |
|
-
|
-
|
RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had…
New
|
CWE-284
Improper Access Control
|
CVE-2024-51988
|
2024-11-7 05:15 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
114
|
- |
|
-
|
-
|
Twig is a template language for PHP. In a sandbox, and attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property poli…
New
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2024-51755
|
2024-11-7 05:15 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
115
|
- |
|
-
|
-
|
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of …
New
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2024-51754
|
2024-11-7 05:15 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
116
|
- |
|
-
|
-
|
Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file conte…
New
|
-
|
CVE-2024-51751
|
2024-11-7 05:15 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
117
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw a…
Update
|
CWE-59
Link Following
|
CVE-2024-9341
|
2024-11-7 05:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
118
|
- |
|
-
|
-
|
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_var…
Update
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-8775
|
2024-11-7 05:15 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
119
|
- |
|
-
|
-
|
Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.
New
|
-
|
CVE-2024-48463
|
2024-11-7 04:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
120
|
- |
|
-
|
-
|
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, Mode…
New
|
-
|
CVE-2024-45185
|
2024-11-7 04:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|