1561
|
8.8 |
HIGH
Network
|
djl
|
deep_java_library
|
A TarSlip vulnerability exists in the deepjavalibrary/djl, affecting version 0.26.0 and fixed in version 0.27.0. This vulnerability allows an attacker to manipulate file paths within tar archives to …
|
CWE-22
Path Traversal
|
CVE-2024-2914
|
2024-09-26 23:12 |
2024-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1562
|
9.8 |
CRITICAL
Network
3rdmill
|
novi_survey
|
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
|
CWE-94
Code Injection
|
CVE-2023-29492
|
2024-09-26 23:10 |
2023-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1563
|
7.2 |
HIGH
Network
|
trendmicro
|
apex_one worry-free_business_security worry-free_business_security_services
|
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an atta…
|
NVD-CWE-noinfo
|
CVE-2023-41179
|
2024-09-26 23:08 |
2023-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1564
|
6.5 |
MEDIUM
Network
|
deno
|
deno
|
An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the registry provided URLs for a tarball on a different dom…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2024-37150
|
2024-09-26 23:04 |
2024-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1565
|
8.8 |
HIGH
Network
|
themekraft
|
buddyforms
|
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to…
|
NVD-CWE-noinfo
|
CVE-2024-8246
|
2024-09-26 23:00 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1566
|
8.8 |
HIGH
Network
|
premmerce
|
premmerce_product_filter_for_woocommerce
|
Missing Authorization vulnerability in Premmerce Premmerce Product Filter for WooCommerce.This issue affects Premmerce Product Filter for WooCommerce: from n/a through 3.7.2.
|
CWE-862
Missing Authorization
|
CVE-2024-31359
|
2024-09-26 22:58 |
2024-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1567
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of t…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-44168
|
2024-09-26 22:56 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1568
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted texture may lead to…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-44161
|
2024-09-26 22:56 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1569
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. A malicious application may be able to access private information.
|
NVD-CWE-noinfo
|
CVE-2024-44163
|
2024-09-26 22:55 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1570
|
7.1 |
HIGH
Local
|
apple
|
macos ipados iphone_os
|
This issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to bypass Privacy preferenc…
|
NVD-CWE-noinfo
|
CVE-2024-44164
|
2024-09-26 22:54 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|