2581
|
5.4 |
MEDIUM
Network
|
mycred
|
mycred_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in myCRED myCred Elementor allows Stored XSS.This issue affects myCred Elementor: from n/a th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49702
|
2024-11-8 23:32 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2582
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Unregister notifier on eswitch init failure
It otherwise remains registered and a subsequent attempt at eswitch
enablin…
|
NVD-CWE-noinfo
|
CVE-2024-50136
|
2024-11-8 23:31 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2583
|
6.5 |
MEDIUM
Network
|
zte
|
zxr10_1800-2s_firmware zxr10_2800-4_firmware zxr10_3800-8_firmware zxr10_160_firmware
|
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the de…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2024-22066
|
2024-11-8 23:31 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2584
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
reset: starfive: jh71x0: Fix accessing the empty member on JH7110 SoC
data->asserted will be NULL on JH7110 SoC since commit 8232…
|
NVD-CWE-noinfo
|
CVE-2024-50137
|
2024-11-8 23:29 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2585
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: Use raw_spinlock_t in ringbuf
The function __bpf_ringbuf_reserve is invoked from a tracepoint, which
disables preemption. Us…
|
NVD-CWE-noinfo
|
CVE-2024-50138
|
2024-11-8 23:27 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2586
|
- |
|
-
|
-
|
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a s…
|
-
|
CVE-2024-7784
|
2024-11-8 18:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2587
|
- |
|
-
|
-
|
Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. …
|
-
|
CVE-2024-6979
|
2024-11-8 18:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2588
|
- |
|
-
|
-
|
Marinus Pfund, member of the AXIS OS Bug Bounty Program,
has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to resource exhaustion of the Axis device.
Axis ha…
|
-
|
CVE-2024-6509
|
2024-11-8 18:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2589
|
- |
|
-
|
-
|
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour confi…
|
-
|
CVE-2024-6173
|
2024-11-8 18:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2590
|
- |
|
-
|
-
|
Marinus Pfund, member of the AXIS OS Bug Bounty Program,
has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of…
|
-
|
CVE-2024-0067
|
2024-11-8 18:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|