1601
|
- |
|
-
|
-
|
The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT transforms performed by various components are vulnerable to XML external entit…
|
CWE-611
XXE
|
CVE-2024-52807
|
2025-01-25 04:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1602
|
- |
|
-
|
-
|
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL in…
|
-
|
CVE-2024-55573
|
2025-01-25 04:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1603
|
- |
|
-
|
-
|
An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection …
|
-
|
CVE-2024-53923
|
2025-01-25 04:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1604
|
- |
|
-
|
-
|
A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP mess…
|
-
|
CVE-2024-24442
|
2025-01-25 04:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1605
|
5.4 |
MEDIUM
Network
|
gambit
|
stackable
|
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the Button block in all versions up to, and including, 3.1…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12117
|
2025-01-25 04:05 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1606
|
5.4 |
MEDIUM
Network
|
aipower
|
aipower
|
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it p…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-13360
|
2025-01-25 03:58 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1607
|
8.8 |
HIGH
Network
|
aipower
|
aipower
|
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including…
|
CWE-862
Missing Authorization
|
CVE-2024-13361
|
2025-01-25 03:55 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1608
|
7.5 |
HIGH
Network
open5gs
|
open5gs
|
A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
|
CWE-617
Reachable Assertion
|
CVE-2024-24427
|
2025-01-25 03:47 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1609
|
7.5 |
HIGH
Network
open5gs
|
open5gs
|
A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.
|
CWE-617
Reachable Assertion
|
CVE-2024-24428
|
2025-01-25 03:44 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1610
|
9.8 |
CRITICAL
Network
wpbot
|
wpot
|
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_file_upload' function in all versions up to, and in…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13091
|
2025-01-25 03:42 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|