41
|
8.8 |
HIGH
Network
|
oretnom23
|
packers_and_movers_management_system
|
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page…
Update
|
CWE-89
SQL Injection
|
CVE-2024-48427
|
2024-10-31 09:07 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
42
|
7.8 |
HIGH
Local
|
google
|
android
|
In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no addi…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47035
|
2024-10-31 09:05 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
43
|
5.5 |
MEDIUM
Local
|
dell
|
data_lakehouse
|
Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with…
Update
|
CWE-89
SQL Injection
|
CVE-2024-47483
|
2024-10-31 09:01 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
44
|
6.5 |
MEDIUM
Adjacent
|
dell
|
data_lakehouse
|
Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerabi…
Update
|
NVD-CWE-Other
|
CVE-2024-47481
|
2024-10-31 09:01 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
45
|
5.4 |
MEDIUM
Network
|
butlerblog
|
wp-members
|
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insuf…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-10374
|
2024-10-31 09:00 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
46
|
9.8 |
CRITICAL
Network
esafenet
|
cdg
|
A vulnerability classified as critical has been found in ESAFENET CDG 5. Affected is the function actionViewCDGRenewFile of the file /com/esafenet/servlet/client/CDGRenewApplicationService.java. The …
Update
|
CWE-89
SQL Injection
|
CVE-2024-10378
|
2024-10-31 08:58 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
47
|
6.5 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may …
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2024-9355
|
2024-10-31 08:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
48
|
- |
|
-
|
-
|
A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and …
New
|
-
|
CVE-2024-10086
|
2024-10-31 07:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
49
|
- |
|
-
|
-
|
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
New
|
-
|
CVE-2024-10006
|
2024-10-31 07:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
50
|
- |
|
-
|
-
|
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.
New
|
-
|
CVE-2024-10005
|
2024-10-31 07:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|