381
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was…
Update
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2023-6736
|
2024-10-9 04:00 |
2024-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
382
|
6.1 |
MEDIUM
Network
|
yoginetwork
|
rabbitloader
|
The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-8800
|
2024-10-9 03:59 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
383
|
5.3 |
MEDIUM
Network
gitlab
|
gitlab
|
A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacke…
Update
|
CWE-862
Missing Authorization
|
CVE-2023-6955
|
2024-10-9 03:59 |
2024-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
384
|
7.5 |
HIGH
Network
wireshark
|
wireshark
|
GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file
Update
|
NVD-CWE-Other
|
CVE-2024-0208
|
2024-10-9 03:58 |
2024-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
385
|
7.5 |
HIGH
Network
wireshark
|
wireshark
|
DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2024-0211
|
2024-10-9 03:57 |
2024-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
386
|
6.1 |
MEDIUM
Network
|
themes4wp
|
popularis_extra
|
The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-9353
|
2024-10-9 03:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
387
|
5.4 |
MEDIUM
Network
|
iworks
|
pwa
|
The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-8967
|
2024-10-9 03:47 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
388
|
7.5 |
HIGH
Network
cisco
|
meraki_mx65_firmware meraki_mx64_firmware meraki_z4c_firmware meraki_z4_firmware meraki_z3c_firmware meraki_z3_firmware meraki_vmx_firmware meraki_mx600_firmware meraki_mx450_…
|
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on …
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-20502
|
2024-10-9 03:46 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
389
|
6.5 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to…
New
|
CWE-89
SQL Injection
|
CVE-2024-9574
|
2024-10-9 03:45 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
390
|
6.5 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the in…
New
|
CWE-89
SQL Injection
|
CVE-2024-9573
|
2024-10-9 03:45 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|