1791
|
- |
|
-
|
-
|
Numbas editor before 7.3 mishandles editing of themes and extensions.
|
-
|
CVE-2024-27612
|
2024-11-2 05:35 |
2024-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1792
|
- |
|
-
|
-
|
This issue was addressed by removing additional entitlements. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.
|
-
|
CVE-2024-23260
|
2024-11-2 05:35 |
2024-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1793
|
- |
|
-
|
-
|
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may…
|
-
|
CVE-2024-22251
|
2024-11-2 05:35 |
2024-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1794
|
- |
|
-
|
-
|
This issue was addressed with improved state management. This issue is fixed in iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to silently persist an Apple ID on an erased dev…
|
-
|
CVE-2023-42855
|
2024-11-2 05:35 |
2024-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1795
|
7.1 |
HIGH
Network
|
lollms
|
lollms_web_ui
|
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from othe…
|
CWE-346
Origin Validation Error
|
CVE-2024-6674
|
2024-11-2 05:34 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1796
|
5.4 |
MEDIUM
Network
|
chartscss
|
coub
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rami Yushuvaev Coub allows Stored XSS.This issue affects Coub: from n/a through 1.4.
|
CWE-79
Cross-site Scripting
|
CVE-2024-49659
|
2024-11-2 05:25 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1797
|
6.1 |
MEDIUM
Network
|
abdullahirfan
|
documentpress
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Abdullah Irfan DocumentPress allows Reflected XSS.This issue affects DocumentPress: from n…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49656
|
2024-11-2 05:24 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1798
|
6.1 |
MEDIUM
Network
|
marianheddesheimer
|
extra_privacy_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marian Heddesheimer Extra Privacy for Elementor allows Reflected XSS.This issue affects Ex…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49654
|
2024-11-2 05:24 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1799
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Deallocate DML memory if allocation fails
[Why]
When DC state create DML memory allocation fails, memory is not
…
|
NVD-CWE-noinfo
|
CVE-2024-49972
|
2024-11-2 05:18 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1800
|
5.4 |
MEDIUM
Network
|
cisco
|
secure_firewall_management_center
|
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack …
|
CWE-79
Cross-site Scripting
|
CVE-2024-20300
|
2024-11-2 05:14 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|