361
|
4.7 |
MEDIUM
Network
|
send_project
|
send
|
Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43799
|
2024-09-21 01:57 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
362
|
7.5 |
HIGH
Network
opendaylight
|
authentication\ _authorization_and_accounting
|
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue con…
|
NVD-CWE-noinfo
|
CVE-2024-46943
|
2024-09-21 01:56 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
363
|
8.8 |
HIGH
Network
|
qnap
|
qts quts_hero
|
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execu…
|
CWE-120 CWE-122
Classic Buffer Overflow Heap-based Buffer Overflow
|
CVE-2024-32763
|
2024-09-21 01:49 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
364
|
4.7 |
MEDIUM
Network
|
qnap
|
qts quts_hero
|
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands …
|
CWE-78
OS Command
|
CVE-2024-21906
|
2024-09-21 01:49 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
365
|
9.8 |
CRITICAL
Network
playsms
|
playsms
|
A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.php?app=main&inc=core_auth&route=forgot&op=forgot …
|
CWE-94
Code Injection
|
CVE-2024-8880
|
2024-09-21 01:41 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
366
|
7.8 |
HIGH
Local
|
qnap
|
qts quts_hero
|
A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated users to access data or perfo…
|
CWE-862
Missing Authorization
|
CVE-2023-39298
|
2024-09-21 01:39 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
367
|
6.1 |
MEDIUM
Network
|
intumit
|
smartrobot_firmware
|
SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting at…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8776
|
2024-09-21 01:38 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
368
|
2.4 |
LOW
Adjacent
|
qnap
|
qts quts_hero
|
An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local networ…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2024-32771
|
2024-09-21 01:38 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
369
|
7.5 |
HIGH
Network
mfasoft
|
secure_authentication_server
|
An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows re…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-46937
|
2024-09-21 01:37 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
370
|
9.8 |
CRITICAL
Network
apache
|
seata
|
Deserialization of Untrusted Data vulnerability in Apache Seata.
When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct unco…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-22399
|
2024-09-21 01:37 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|