411
|
7.5 |
HIGH
Network
micropython
|
micropython
|
A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffe…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2024-8948
|
2024-09-24 03:10 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
412
|
8.8 |
HIGH
Network
|
oretnom23
|
online_eyewear_shop
|
A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart Content Handler. Th…
Update
|
CWE-282
Improper Ownership Management
|
CVE-2024-8949
|
2024-09-24 03:05 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
413
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Update
|
NVD-CWE-noinfo
|
CVE-2024-8908
|
2024-09-24 02:59 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
414
|
6.1 |
MEDIUM
Network
|
netcat
|
netcat_content_management_system
|
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site.
This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-8653
|
2024-09-24 02:55 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
415
|
6.1 |
MEDIUM
Network
|
netcat
|
netcat_content_management_system
|
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site.
This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-8652
|
2024-09-24 02:53 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
416
|
5.3 |
MEDIUM
Network
netcat
|
netcat_content_management_system
|
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks.
Th…
Update
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-8651
|
2024-09-24 02:51 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
417
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Update
|
NVD-CWE-noinfo
|
CVE-2024-8909
|
2024-09-24 02:51 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
418
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML p…
Update
|
NVD-CWE-noinfo
|
CVE-2024-8906
|
2024-09-24 02:38 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
419
|
- |
|
-
|
-
|
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.
New
|
-
|
CVE-2024-41228
|
2024-09-24 02:35 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
420
|
- |
|
-
|
-
|
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.
New
|
-
|
CVE-2024-34331
|
2024-09-24 02:35 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|