731
|
9.8 |
CRITICAL
Network
-
|
-
|
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device…
|
CWE-78
OS Command
|
CVE-2024-11120
|
2024-11-15 11:15 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
732
|
9.1 |
CRITICAL
Network
paloaltonetworks
|
expedition
|
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, a…
|
CWE-89
SQL Injection
|
CVE-2024-9465
|
2024-11-15 11:00 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
733
|
7.5 |
HIGH
Network
paloaltonetworks
|
expedition
|
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cle…
|
CWE-78
OS Command
|
CVE-2024-9463
|
2024-11-15 11:00 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
734
|
- |
|
-
|
-
|
The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been …
|
CWE-77
Command Injection
|
CVE-2024-52308
|
2024-11-15 10:15 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
735
|
5.4 |
MEDIUM
Network
|
ladybirdweb
|
faveo_helpdesk
|
An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields
|
CWE-79
Cross-site Scripting
|
CVE-2024-51377
|
2024-11-15 08:23 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
736
|
9.8 |
CRITICAL
Network
olivegroup
|
olivevle
|
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2024-48428
|
2024-11-15 08:15 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
737
|
7.5 |
HIGH
Network
plenti
|
plenti
|
Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti use…
|
CWE-22
Path Traversal
|
CVE-2024-49381
|
2024-11-15 08:04 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
738
|
8.8 |
HIGH
Network
|
autolabproject
|
autolab
|
Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient…
|
CWE-863
Incorrect Authorization
|
CVE-2024-49376
|
2024-11-15 07:49 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
739
|
- |
|
-
|
-
|
An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port 7412 on the network. All the network services of the gateway become unresponsiv…
|
-
|
CVE-2024-23765
|
2024-11-15 07:35 |
2024-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
740
|
- |
|
-
|
-
|
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 1…
|
-
|
CVE-2023-5388
|
2024-11-15 07:35 |
2024-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|