271
|
8.8 |
HIGH
Network
|
infoblox
|
nios
|
Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access.
Update
|
NVD-CWE-noinfo
|
CVE-2023-37249
|
2024-10-3 04:35 |
2023-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272
|
7.5 |
HIGH
Network
apache
|
inlong
|
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.
The attacker could bypass the current logic a…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2023-34434
|
2024-10-3 04:35 |
2023-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
273
|
9.8 |
CRITICAL
Network
apache
|
shiro
|
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route re…
Update
|
CWE-22
Path Traversal
|
CVE-2023-34478
|
2024-10-3 04:35 |
2023-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
274
|
8.8 |
HIGH
Network
|
apache
|
shardingsphere
|
Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file.
The attacker needs…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2023-28754
|
2024-10-3 04:35 |
2023-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275
|
5.4 |
MEDIUM
Network
|
gutengeek
|
free_gutenberg_blocks
|
The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.3 due to insufficien…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-9073
|
2024-10-3 04:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276
|
4.3 |
MEDIUM
Network
|
themesflat
|
themesflat_addons_for_elementor
|
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authen…
Update
|
NVD-CWE-noinfo
|
CVE-2024-8516
|
2024-10-3 04:22 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
277
|
5.4 |
MEDIUM
Network
|
themesflat
|
themesflat_addons_for_elementor
|
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in al…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-8515
|
2024-10-3 04:22 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
278
|
- |
|
-
|
-
|
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id pa…
New
|
-
|
CVE-2024-9441
|
2024-10-3 04:15 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
279
|
- |
|
-
|
-
|
Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned…
New
|
-
|
CVE-2024-9440
|
2024-10-3 04:15 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
280
|
- |
|
-
|
-
|
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
New
|
-
|
CVE-2024-24116
|
2024-10-3 04:15 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|