761
|
5.3 |
MEDIUM
Network
hashicorp
|
nomad
|
HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in …
|
CWE-862
Missing Authorization
|
CVE-2023-3300
|
2024-09-27 06:15 |
2023-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
762
|
2.7 |
LOW
Network
|
hashicorp
|
nomad
|
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2023-3299
|
2024-09-27 06:15 |
2023-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
763
|
7.5 |
HIGH
Network
openplcproject
|
openplc_v3_firmware
|
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2024-39590
|
2024-09-27 06:02 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
764
|
7.5 |
HIGH
Network
openplcproject
|
openplc_v3_firmware
|
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-36981
|
2024-09-27 05:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
765
|
7.5 |
HIGH
Network
openplcproject
|
openplc_v3_firmware
|
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-36980
|
2024-09-27 05:53 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
766
|
9.8 |
CRITICAL
Network
openplcproject
|
openplc_v3_firmware
|
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP req…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-34026
|
2024-09-27 05:52 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
767
|
6.1 |
MEDIUM
Network
|
microsoft
|
edge
|
Microsoft Edge (Chromium-based) Spoofing Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38156
|
2024-09-27 05:41 |
2024-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
768
|
4.8 |
MEDIUM
Network
|
cminds
|
cm_popup
|
The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Script…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5799
|
2024-09-27 05:39 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
769
|
4.8 |
MEDIUM
Network
|
seedprod
|
rafflepress
|
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege users such as editor and above…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6887
|
2024-09-27 05:38 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
770
|
7.2 |
HIGH
Network
|
erichamby
|
adicon_server
|
The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
|
CWE-89
SQL Injection
|
CVE-2024-7766
|
2024-09-27 05:37 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|