321
|
9.8 |
CRITICAL
Network
-
|
-
|
Rejected reason: Duplicate of CVE-2024-45806.
Update
|
-
|
CVE-2024-7207
|
2024-10-1 04:15 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
322
|
9.8 |
CRITICAL
Network
github
|
enterprise_server
|
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation met…
Update
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-6800
|
2024-10-1 04:14 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
323
|
5.3 |
MEDIUM
Network
coffee2code
|
custom_post_limits
|
The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plugin utilizing bootstrap and leaving test files wit…
Update
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-6544
|
2024-10-1 04:12 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
324
|
6.5 |
MEDIUM
Network
|
moxa
|
mxview_one
|
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of s…
Update
|
CWE-22
Path Traversal
|
CVE-2024-6786
|
2024-10-1 03:31 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
325
|
4.3 |
MEDIUM
Network
|
cilium
|
cilium
|
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoute…
Update
|
CWE-436
Interpretation Conflict
|
CVE-2024-42487
|
2024-10-1 03:31 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
326
|
- |
|
-
|
-
|
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber paramete…
New
|
-
|
CVE-2024-46635
|
2024-10-1 03:15 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
327
|
- |
|
-
|
-
|
An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an…
New
|
-
|
CVE-2024-42017
|
2024-10-1 03:15 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
328
|
- |
|
-
|
-
|
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing ne…
New
|
-
|
CVE-2024-35495
|
2024-10-1 03:15 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
329
|
8.8 |
HIGH
Network
|
givewp
|
givewp
|
Cross-Site Request Forgery (CSRF) vulnerability in GiveWP.This issue affects GiveWP: from n/a through 3.15.1.
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-47315
|
2024-10-1 03:06 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
330
|
8.8 |
HIGH
Network
|
lobehub
|
lobe_chat
|
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redi…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-47066
|
2024-10-1 03:03 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|