1
|
- |
|
-
|
-
|
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, …
Update
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2024-3727
|
2024-10-2 08:15 |
2024-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2
|
6.1 |
MEDIUM
Network
|
ckeditor
|
ckeditor5
|
CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vu…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-45613
|
2024-10-2 07:15 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
3
|
- |
|
-
|
-
|
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-9411
|
2024-10-2 06:35 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4
|
9.8 |
CRITICAL
Network
totolink
|
a3300r_firmware
|
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.
Update
|
CWE-78
OS Command
|
CVE-2024-23058
|
2024-10-2 06:35 |
2024-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
5
|
9.8 |
CRITICAL
Network
tenda
|
ax1803_firmware
|
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2023-51958
|
2024-10-2 06:35 |
2024-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
6
|
7.8 |
HIGH
Local
|
archive_project
|
archive
|
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
Update
|
NVD-CWE-noinfo
|
CVE-2023-39137
|
2024-10-2 06:35 |
2023-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
7
|
5.5 |
MEDIUM
Local
|
ziparchive_project
|
ziparchive
|
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
Update
|
NVD-CWE-noinfo
|
CVE-2023-39136
|
2024-10-2 06:35 |
2023-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
8
|
4.7 |
MEDIUM
Local
|
-
|
-
|
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrar…
New
|
CWE-20
Improper Input Validation
|
CVE-2024-9407
|
2024-10-2 06:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
9
|
- |
|
-
|
-
|
Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting…
New
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-47609
|
2024-10-2 06:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
10
|
- |
|
-
|
-
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users with "admin" role c…
New
|
CWE-79 CWE-116 CWE-434
Cross-site Scripting Improper Encoding or Escaping of Output Unrestricted Upload of File with Dangerous Type
|
CVE-2024-47528
|
2024-10-2 06:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|