991
|
5.5 |
MEDIUM
Local
|
apple
|
macos ipados iphone_os watchos
|
This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 11.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, iOS 18.1 and iPadOS 18.1. An app may be able…
Update
|
NVD-CWE-noinfo
|
CVE-2024-44254
|
2024-10-31 06:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
992
|
4.6 |
MEDIUM
Physics
|
apple
|
ipados iphone_os
|
The issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.
Update
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-44235
|
2024-10-31 06:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
993
|
7.8 |
HIGH
Local
|
apple
|
macos ipados iphone_os visionos
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sequoia 15, iOS 17.7 and iPadOS 17.7, macOS Sonoma 14.7, visionOS 2, iOS 18 and iPadOS 18. Processing …
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44126
|
2024-10-31 06:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
994
|
- |
|
-
|
-
|
PbootCMS 3.2.8 is vulnerable to URL Redirect.
Update
|
-
|
CVE-2024-42930
|
2024-10-31 06:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
995
|
- |
|
-
|
-
|
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.
Update
|
-
|
CVE-2024-39205
|
2024-10-31 06:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
996
|
- |
|
-
|
-
|
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to job…
Update
|
-
|
CVE-2024-48936
|
2024-10-31 06:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
997
|
- |
|
-
|
-
|
ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.e…
Update
|
-
|
CVE-2024-50624
|
2024-10-31 06:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
998
|
- |
|
-
|
-
|
In Cleo Harmony before 5.8.0.20, VLTrader before 5.8.0.20, and LexiCom before 5.8.0.20, there is a JavaScript Injection vulnerability: unrestricted file upload and download could lead to remote code …
Update
|
-
|
CVE-2024-50623
|
2024-10-31 06:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
999
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security seve…
Update
|
NVD-CWE-noinfo
|
CVE-2024-7974
|
2024-10-31 06:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1000
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr
|
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header pr…
Update
|
NVD-CWE-noinfo
|
CVE-2024-7531
|
2024-10-31 06:35 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|