1511
|
7.5 |
HIGH
Network
openplcproject
|
openplc_v3_firmware
|
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-36981
|
2024-09-27 05:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1512
|
7.5 |
HIGH
Network
openplcproject
|
openplc_v3_firmware
|
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-36980
|
2024-09-27 05:53 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1513
|
9.8 |
CRITICAL
Network
openplcproject
|
openplc_v3_firmware
|
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP req…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-34026
|
2024-09-27 05:52 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1514
|
6.1 |
MEDIUM
Network
|
microsoft
|
edge
|
Microsoft Edge (Chromium-based) Spoofing Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38156
|
2024-09-27 05:41 |
2024-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1515
|
4.8 |
MEDIUM
Network
|
cminds
|
cm_popup
|
The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Script…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5799
|
2024-09-27 05:39 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1516
|
4.8 |
MEDIUM
Network
|
seedprod
|
rafflepress
|
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege users such as editor and above…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6887
|
2024-09-27 05:38 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1517
|
7.2 |
HIGH
Network
|
erichamby
|
adicon_server
|
The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
|
CWE-89
SQL Injection
|
CVE-2024-7766
|
2024-09-27 05:37 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1518
|
6.4 |
MEDIUM
Local
|
arubanetworks
|
arubaos
|
A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass security controls which would normally prohibit unsigned…
|
CWE-863
Incorrect Authorization
|
CVE-2023-38486
|
2024-09-27 05:35 |
2023-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1519
|
5.3 |
MEDIUM
Network
jenkins
|
pipeline_maven_integration
|
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline …
|
NVD-CWE-noinfo
|
CVE-2023-41934
|
2024-09-27 05:35 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1520
|
5.4 |
MEDIUM
Network
|
nattywp
|
delicate
|
The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme's Button shortcode in all versions up to, and including, 3.5.5 due to insuffici…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5867
|
2024-09-27 05:32 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|