221
|
- |
|
-
|
-
|
The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old…
New
|
-
|
CVE-2024-10815
|
2025-01-10 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
222
|
- |
|
-
|
-
|
An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.
New
|
-
|
CVE-2024-46603
|
2025-01-10 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
223
|
- |
|
-
|
-
|
An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a cra…
New
|
-
|
CVE-2024-46602
|
2025-01-10 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
224
|
- |
|
-
|
-
|
Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.
New
|
-
|
CVE-2024-46601
|
2025-01-10 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
225
|
5.5 |
MEDIUM
Local
|
dell
|
powerscale_onefs
|
Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerab…
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-47475
|
2025-01-10 01:04 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
226
|
- |
|
-
|
-
|
A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer.
New
|
-
|
CVE-2024-10106
|
2025-01-10 00:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
227
|
- |
|
-
|
-
|
IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users.
New
|
CWE-282 CWE-276
Improper Ownership Management Incorrect Default Permissions
|
CVE-2024-43176
|
2025-01-10 00:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
228
|
- |
|
-
|
-
|
IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, and 12.4 operands running in Red H…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2022-22491
|
2025-01-10 00:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
229
|
- |
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to Cross-Site Request Fo…
New
|
-
|
CVE-2024-12605
|
2025-01-10 00:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
230
|
- |
|
-
|
-
|
SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Mic…
New
|
-
|
CVE-2024-12802
|
2025-01-10 00:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|