791
|
6.5 |
MEDIUM
Network
|
deno
|
deno
|
An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the registry provided URLs for a tarball on a different dom…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2024-37150
|
2024-09-26 23:04 |
2024-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
792
|
8.8 |
HIGH
Network
|
themekraft
|
buddyforms
|
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to…
|
NVD-CWE-noinfo
|
CVE-2024-8246
|
2024-09-26 23:00 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
793
|
8.8 |
HIGH
Network
|
premmerce
|
premmerce_product_filter_for_woocommerce
|
Missing Authorization vulnerability in Premmerce Premmerce Product Filter for WooCommerce.This issue affects Premmerce Product Filter for WooCommerce: from n/a through 3.7.2.
|
CWE-862
Missing Authorization
|
CVE-2024-31359
|
2024-09-26 22:58 |
2024-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
794
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of t…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-44168
|
2024-09-26 22:56 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
795
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted texture may lead to…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-44161
|
2024-09-26 22:56 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
796
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. A malicious application may be able to access private information.
|
NVD-CWE-noinfo
|
CVE-2024-44163
|
2024-09-26 22:55 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
797
|
7.1 |
HIGH
Local
|
apple
|
macos ipados iphone_os
|
This issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to bypass Privacy preferenc…
|
NVD-CWE-noinfo
|
CVE-2024-44164
|
2024-09-26 22:54 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
798
|
7.5 |
HIGH
Network
apple
|
macos iphone_os ipados visionos
|
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. Network t…
|
NVD-CWE-noinfo
|
CVE-2024-44165
|
2024-09-26 22:53 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
799
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access user-s…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-44166
|
2024-09-26 22:47 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
800
|
5.4 |
MEDIUM
Network
|
elizsoftware
|
panel
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS.This issue affects Panel: before v2.3.24.
|
CWE-79
Cross-site Scripting
|
CVE-2024-5959
|
2024-09-26 22:39 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|