541
|
5.3 |
MEDIUM
Network
phoenixcontact
|
fl_mguard_2102_firmware fl_mguard_4102_pci_firmware fl_mguard_4102_pcie_firmware fl_mguard_4302_firmware fl_mguard_centerport_firmware fl_mguard_centerport_vpn-1000_firmware fl_mgua…
|
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the …
Update
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2023-2673
|
2024-10-2 15:15 |
2023-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
542
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7855
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
543
|
- |
|
-
|
-
|
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.
New
|
-
|
CVE-2024-45186
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
544
|
- |
|
-
|
-
|
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
New
|
-
|
CVE-2024-33662
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
545
|
- |
|
-
|
-
|
Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the …
New
|
-
|
CVE-2024-21530
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
546
|
6.1 |
MEDIUM
Network
|
ckeditor
|
ckeditor5
|
CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vu…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-45613
|
2024-10-2 07:15 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
547
|
- |
|
-
|
-
|
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-9411
|
2024-10-2 06:35 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
548
|
9.8 |
CRITICAL
Network
totolink
|
a3300r_firmware
|
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.
Update
|
CWE-78
OS Command
|
CVE-2024-23058
|
2024-10-2 06:35 |
2024-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
549
|
9.8 |
CRITICAL
Network
tenda
|
ax1803_firmware
|
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2023-51958
|
2024-10-2 06:35 |
2024-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
550
|
7.8 |
HIGH
Local
|
archive_project
|
archive
|
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
Update
|
NVD-CWE-noinfo
|
CVE-2023-39137
|
2024-10-2 06:35 |
2023-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|