551
|
- |
|
-
|
-
|
The goTenna Pro ATAK Plugin has a payload length vulnerability that
makes it possible to tell the length of the payload regardless of the
encryption used.
|
CWE-204
Response Discrepancy Information Exposure
|
CVE-2024-41715
|
2024-09-27 03:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
552
|
- |
|
-
|
-
|
Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low p…
|
CWE-77
Command Injection
|
CVE-2024-39577
|
2024-09-27 03:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
553
|
7.5 |
HIGH
Network
hashicorp
|
nomad
|
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerabi…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2024-1329
|
2024-09-27 03:15 |
2024-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
554
|
8.8 |
HIGH
Network
|
sirv
|
sirv
|
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in al…
|
CWE-862
Missing Authorization
|
CVE-2024-8480
|
2024-09-27 03:13 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
555
|
8.8 |
HIGH
Network
|
bitapps
|
file_manager
|
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'uplo…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7770
|
2024-09-27 02:49 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
556
|
6.1 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-46934
|
2024-09-27 02:41 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
557
|
9.8 |
CRITICAL
Network
wpcom
|
wpcom_member
|
The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_…
|
NVD-CWE-noinfo
|
CVE-2024-7493
|
2024-09-27 02:41 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
558
|
7.5 |
HIGH
Network
rocket.chat
|
rocket.chat
|
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an …
|
NVD-CWE-noinfo
|
CVE-2024-46935
|
2024-09-27 02:39 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
559
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext…
|
CWE-316
Cleartext Storage of Sensitive Information in Memory
|
CVE-2024-9203
|
2024-09-27 02:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
560
|
- |
|
-
|
-
|
The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing…
|
CWE-78
OS Command
|
CVE-2024-9166
|
2024-09-27 02:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|