171
|
- |
|
-
|
-
|
Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the …
New
|
-
|
CVE-2024-21530
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
172
|
6.1 |
MEDIUM
Network
|
ckeditor
|
ckeditor5
|
CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vu…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-45613
|
2024-10-2 07:15 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
173
|
- |
|
-
|
-
|
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-9411
|
2024-10-2 06:35 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
174
|
9.8 |
CRITICAL
Network
totolink
|
a3300r_firmware
|
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.
Update
|
CWE-78
OS Command
|
CVE-2024-23058
|
2024-10-2 06:35 |
2024-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
175
|
9.8 |
CRITICAL
Network
tenda
|
ax1803_firmware
|
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2023-51958
|
2024-10-2 06:35 |
2024-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
176
|
7.8 |
HIGH
Local
|
archive_project
|
archive
|
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
Update
|
NVD-CWE-noinfo
|
CVE-2023-39137
|
2024-10-2 06:35 |
2023-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
177
|
5.5 |
MEDIUM
Local
|
ziparchive_project
|
ziparchive
|
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
Update
|
NVD-CWE-noinfo
|
CVE-2023-39136
|
2024-10-2 06:35 |
2023-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
178
|
4.7 |
MEDIUM
Local
|
-
|
-
|
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrar…
New
|
CWE-20
Improper Input Validation
|
CVE-2024-9407
|
2024-10-2 06:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
179
|
- |
|
-
|
-
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-47527
|
2024-10-2 06:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
180
|
- |
|
-
|
-
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary Java…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-47526
|
2024-10-2 06:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|