1121
|
5.3 |
MEDIUM
Network
atlassian
|
confluence_data_center confluence_server
|
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Informa…
|
NVD-CWE-noinfo
|
CVE-2023-22503
|
2024-10-2 01:35 |
2023-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1122
|
5.4 |
MEDIUM
Network
|
strangerstudios
|
paid_memberships_pro
|
The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as lo…
|
CWE-79
Cross-site Scripting
|
CVE-2022-4830
|
2024-10-2 01:35 |
2023-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1123
|
5.4 |
MEDIUM
Network
|
3dflipbook
|
3d_flipbook
|
The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Con…
|
CWE-79
Cross-site Scripting
|
CVE-2022-4453
|
2024-10-2 01:35 |
2023-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1124
|
9.8 |
CRITICAL
Network
doverfuelingsolutions
|
progauge_maglink_lx_console_firmware progauge_maglink_lx4_console_firmware
|
An attacker can directly request the ProGauge MAGLINK LX CONSOLE
resource sub page with full privileges by requesting the URL directly.
|
NVD-CWE-Other
|
CVE-2024-43692
|
2024-10-2 01:22 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1125
|
9.8 |
CRITICAL
Network
doverfuelingsolutions
|
progauge_maglink_lx_console_firmware progauge_maglink_lx4_console_firmware
|
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP
sub-menu can allow a remote attacker to inject arbitrary commands.
|
CWE-77
Command Injection
|
CVE-2024-45066
|
2024-10-2 01:18 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1126
|
7.5 |
HIGH
Network
mozilla
|
firefox
|
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and T…
|
NVD-CWE-noinfo
|
CVE-2024-8900
|
2024-10-2 01:15 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1127
|
8.8 |
HIGH
Network
|
doverfuelingsolutions
|
progauge_maglink_lx_console_firmware progauge_maglink_lx4_console_firmware
|
Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.
|
NVD-CWE-noinfo
|
CVE-2024-45373
|
2024-10-2 01:13 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1128
|
9.1 |
CRITICAL
Network
watchguard
|
single_sign-on_client authentication_gateway
|
Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Win…
|
CWE-863
Incorrect Authorization
|
CVE-2024-6592
|
2024-10-2 01:06 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1129
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: phy: dp83822: Fix NULL pointer dereference on DP83825 devices
The probe() function is only used for DP83822 and DP83826 PHY,…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46856
|
2024-10-2 01:04 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1130
|
9.1 |
CRITICAL
Network
ptzoptics
|
pt30x-sdi_firmware pt30x-ndi-xx-g2_firmware
|
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are se…
|
CWE-287
Improper Authentication
|
CVE-2024-8956
|
2024-10-2 01:01 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|