41
|
7.5 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-se…
New
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2020-25720
|
2024-11-17 20:15 |
2024-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
42
|
- |
|
-
|
-
|
Rejected reason: This issue is not a vulnerability because no real attack scenario can happen.
Update
|
-
|
CVE-2024-21540
|
2024-11-17 18:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
43
|
- |
|
-
|
-
|
Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read o…
New
|
-
|
CVE-2024-52876
|
2024-11-17 14:15 |
2024-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
44
|
- |
|
-
|
-
|
In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.
New
|
-
|
CVE-2024-52872
|
2024-11-17 13:15 |
2024-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
45
|
- |
|
-
|
-
|
In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.
New
|
-
|
CVE-2024-52871
|
2024-11-17 13:15 |
2024-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
46
|
- |
|
-
|
-
|
guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properl…
New
|
-
|
CVE-2024-52867
|
2024-11-17 12:15 |
2024-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
47
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post allows Upload a Web Shell to a Web Server.This issue affects Convert Docx2post: from n/a through 1.4.
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-52397
|
2024-11-17 08:15 |
2024-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
48
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Eugen Bobrowski Debug Tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through 2.2.
New
|
CWE-862
Missing Authorization
|
CVE-2024-52416
|
2024-11-17 07:15 |
2024-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
49
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Skpstorm SK WP Settings Backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through 1.0.
New
|
CWE-352
Origin Validation Error
|
CVE-2024-52415
|
2024-11-17 07:15 |
2024-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
50
|
- |
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu allows Object Injection.This issue affects WDES Responsive Mobile Menu: from n/a through 5.3.18.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-52414
|
2024-11-17 07:15 |
2024-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|