1901
|
7.5 |
HIGH
Network
trianglemicroworks siemens
|
iec_61850_source_code_library sicam_a8000_firmware sicam_scc_firmware sicam_egs_firmware sicam_s8000 sitipe_at
|
Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in …
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-34057
|
2024-09-26 02:08 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1902
|
8.8 |
HIGH
Network
|
frogcms_project
|
frogcms
|
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123
|
CWE-352
Origin Validation Error
|
CVE-2024-46086
|
2024-09-26 02:08 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1903
|
7.5 |
HIGH
Network
quinn_project
|
quinn
|
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, `refuse()`, or `ignore()` an `…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2024-45311
|
2024-09-26 02:03 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1904
|
7.5 |
HIGH
Network
linlinjava
|
litemall
|
A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminGoodscontroller.java.
|
CWE-89
SQL Injection
|
CVE-2024-46382
|
2024-09-26 01:56 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1905
|
8.8 |
HIGH
Network
|
frogcms_project
|
frogcms
|
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
|
CWE-352
Origin Validation Error
|
CVE-2024-46394
|
2024-09-26 01:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1906
|
7.3 |
HIGH
Local
|
pixlone
|
logiops
|
logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, including setting malicious keyboard macros. This al…
|
NVD-CWE-noinfo
|
CVE-2024-45752
|
2024-09-26 01:54 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1907
|
5.4 |
MEDIUM
Network
|
workdo
|
crmgo_saas
|
A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affects some unknown processing of the file /project/task/{task_id}/show. The manip…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9031
|
2024-09-26 01:52 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1908
|
3.3 |
LOW
Local
|
apple
|
macos
|
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15. A malicious app may be able to access notifications from the user's device.
|
NVD-CWE-noinfo
|
CVE-2024-40838
|
2024-09-26 01:46 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1909
|
6.5 |
MEDIUM
Network
|
zitadel
|
zitadel
|
Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across other o…
|
CWE-863
Incorrect Authorization
|
CVE-2024-47060
|
2024-09-26 01:43 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1910
|
8.8 |
HIGH
Network
|
code4recovery
|
12_step_meeting_list
|
Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28.
|
CWE-862
Missing Authorization
|
CVE-2024-22296
|
2024-09-26 01:36 |
2024-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|