1631
|
4.4 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to…
|
CWE-22
Path Traversal
|
CVE-2024-9675
|
2024-11-13 17:15 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1632
|
- |
|
-
|
-
|
CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become
unresponsive resulting in communication loss when a large amount of IGMP packets is present in…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-9409
|
2024-11-13 14:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1633
|
- |
|
-
|
-
|
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could
cause a potential arbitrary code execution after a successful Man-In-The-Middle attack…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2024-8938
|
2024-11-13 14:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1634
|
- |
|
-
|
-
|
All versions of the package dom-iterator are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body …
|
-
|
CVE-2024-21541
|
2024-11-13 14:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1635
|
9.8 |
CRITICAL
Network
-
|
-
|
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to…
|
CWE-22
Path Traversal
|
CVE-2024-11150
|
2024-11-13 14:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1636
|
8.8 |
HIGH
Network
|
-
|
-
|
The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields() function in all versions up to, and including, 1…
|
CWE-862
Missing Authorization
|
CVE-2024-10800
|
2024-11-13 14:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1637
|
- |
|
-
|
-
|
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on
the network and potentially impacting connected devices.
|
CWE-862
Missing Authorization
|
CVE-2024-10575
|
2024-11-13 14:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1638
|
- |
|
-
|
-
|
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could
cause a potential arbitrary code execution after a successful Man-In-The Middle attack…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2024-8937
|
2024-11-13 14:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1639
|
- |
|
-
|
-
|
CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory
after a successful Man-In-The-Middle attack followed by sending a crafted Modbus…
|
CWE-20
Improper Input Validation
|
CVE-2024-8936
|
2024-11-13 14:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1640
|
- |
|
-
|
-
|
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss
of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attac…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2024-8935
|
2024-11-13 14:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|