1481
|
9.8 |
CRITICAL
Network
arris
|
tg852g_firmware tg862g_firmware tg1672g_firmware
|
An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.
|
NVD-CWE-noinfo
|
CVE-2023-40039
|
2024-09-27 01:35 |
2023-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1482
|
7.5 |
HIGH
Network
hamza417
|
inure
|
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.
|
NVD-CWE-noinfo
|
CVE-2023-4876
|
2024-09-27 01:35 |
2023-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1483
|
5.3 |
MEDIUM
Network
hcltech
|
domino
|
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
|
NVD-CWE-noinfo
|
CVE-2023-28010
|
2024-09-27 01:35 |
2023-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1484
|
9.8 |
CRITICAL
Network
code-projects
|
student_record_system
|
A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an unknown function of the file /pincode-verification.php. The manipulation of th…
|
CWE-89
SQL Injection
|
CVE-2024-9080
|
2024-09-27 01:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1485
|
9.8 |
CRITICAL
Network
code-projects
|
student_record_system
|
A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /marks.php. The manipulation of the argument co…
|
CWE-89
SQL Injection
|
CVE-2024-9079
|
2024-09-27 01:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1486
|
9.8 |
CRITICAL
Network
code-projects
|
student_record_system
|
A vulnerability has been found in code-projects Student Record System 1.0 and classified as critical. This vulnerability affects unknown code of the file /course.php. The manipulation of the argument…
|
CWE-89
SQL Injection
|
CVE-2024-9078
|
2024-09-27 01:31 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1487
|
4.3 |
MEDIUM
Network
|
infiniteuploads
|
big_file_uploads
|
The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1.2. This is due the plugin not sanitizing …
|
CWE-22
Path Traversal
|
CVE-2024-8538
|
2024-09-27 01:28 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1488
|
9.8 |
CRITICAL
Network
wpcharitable
|
charitable
|
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. Thi…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8791
|
2024-09-27 01:25 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1489
|
5.3 |
MEDIUM
Network
ba-booking
|
ba_book_everything
|
The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a u…
|
NVD-CWE-Other
|
CVE-2024-8794
|
2024-09-27 01:23 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1490
|
6.1 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms_file_uploads
|
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient …
|
CWE-79
Cross-site Scripting
|
CVE-2024-1596
|
2024-09-27 01:23 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|