601
|
- |
|
-
|
-
|
In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereference occurring in all subsequent operations that require authe…
|
-
|
CVE-2024-57435
|
2025-02-4 06:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
602
|
- |
|
-
|
-
|
macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super administrator.
|
-
|
CVE-2024-57434
|
2025-02-4 06:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
603
|
- |
|
-
|
-
|
Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProject functions.
|
-
|
CVE-2024-53320
|
2025-02-4 06:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
604
|
- |
|
-
|
-
|
Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the server from accepting new DNS-over-QUIC connections by triggering unhandled exce…
|
-
|
CVE-2024-56946
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
605
|
8.8 |
HIGH
Network
|
-
|
-
|
The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8.0 via the 'boombox_listing' shortcode 'type' attribute. This makes it…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2024-12859
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
606
|
- |
|
-
|
-
|
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.
|
-
|
CVE-2024-12511
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
607
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to, and including, 3.9…
|
CWE-862
Missing Authorization
|
CVE-2024-11134
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
608
|
5.3 |
MEDIUM
Network
-
|
-
|
The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9…
|
CWE-862
Missing Authorization
|
CVE-2024-11133
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
609
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.9.9 due to insufficient input sanitization and output escaping on user…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11132
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
610
|
- |
|
-
|
-
|
If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.
|
-
|
CVE-2024-12510
|
2025-02-4 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|