1481
|
- |
|
-
|
-
|
A CWE-862 “Missing Authorization” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. This issue a…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2023-45598
|
2024-09-30 19:15 |
2024-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1482
|
- |
|
-
|
-
|
A CWE-862 “Missing Authorization” vulnerability in the “file_configuration” functionality of the web application allows a remote unauthenticated attacker to access confidential configuration files. T…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2023-45596
|
2024-09-30 19:15 |
2024-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1483
|
- |
|
-
|
-
|
A CWE-693 “Protection Mechanism Failure” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allows a physical attacker to re…
|
CWE-184
Incomplete Blacklist
|
CVE-2023-45593
|
2024-09-30 19:15 |
2024-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1484
|
8.1 |
HIGH
Adjacent
|
bluemark
|
dronescout_ds230_firmware
|
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection.
An attacker can exploit this vulnerability by injecting, on …
|
CWE-223
|
CVE-2023-31191
|
2024-09-30 19:15 |
2023-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1485
|
8.1 |
HIGH
Network
|
bluemark
|
dronescout_ds230_firmware
|
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure.
Specifically, the firmware update procedur…
|
CWE-295
Improper Certificate Validation
|
CVE-2023-31190
|
2024-09-30 19:15 |
2023-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1486
|
6.8 |
MEDIUM
Adjacent
|
bluemark
|
dronescout_ds230_firmware
|
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection.
An attacker can exploit this vulnerability by injecting, at t…
|
CWE-223
|
CVE-2023-29156
|
2024-09-30 19:15 |
2023-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1487
|
- |
|
-
|
-
|
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifyin…
|
-
|
CVE-2024-9329
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1488
|
- |
|
-
|
-
|
A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allow…
|
CWE-29
Path Traversal: '\..\filename'
|
CVE-2024-6394
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1489
|
- |
|
-
|
-
|
In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-based buffer overflow upon deserialization of session informatio…
|
-
|
CVE-2024-45200
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1490
|
- |
|
-
|
-
|
Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may re…
|
-
|
CVE-2024-42496
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|