191
|
4.7 |
MEDIUM
Network
|
ovaledge
|
ovaledge
|
OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADM…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2022-30356
|
2024-11-1 01:31 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
192
|
6.1 |
MEDIUM
Network
|
rimonhabib
|
bp_member_type_manager
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager allows Reflected XSS.This issue affects BP Member Type …
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-49634
|
2024-11-1 01:30 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
193
|
4.3 |
MEDIUM
Network
|
gaizhenbiao
|
chuanhuchatgpt
|
In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a…
New
|
NVD-CWE-noinfo
|
CVE-2024-8143
|
2024-11-1 01:23 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
194
|
- |
|
-
|
-
|
Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster jo…
New
|
-
|
CVE-2024-8185
|
2024-11-1 01:15 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
195
|
- |
|
-
|
-
|
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.
New
|
-
|
CVE-2024-51260
|
2024-11-1 01:15 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
196
|
- |
|
-
|
-
|
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function.
New
|
-
|
CVE-2024-51255
|
2024-11-1 01:15 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
197
|
- |
|
-
|
-
|
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot …
New
|
-
|
CVE-2024-50354
|
2024-11-1 01:15 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
198
|
7.5 |
HIGH
Network
gaizhenbiao
|
chuanhuchatgpt
|
An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matche…
New
|
CWE-22
Path Traversal
|
CVE-2024-7962
|
2024-11-1 01:14 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
199
|
6.1 |
MEDIUM
Network
|
tidaweb
|
tida_url_screenshot
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tidaweb Tida URL Screenshot allows Reflected XSS.This issue affects Tida URL Screenshot: f…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-49641
|
2024-11-1 01:05 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
200
|
6.1 |
MEDIUM
Network
|
amadercodelab
|
acl_floating_cart_for_woocommerce
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AmaderCode Lab ACL Floating Cart for WooCommerce allows Reflected XSS.This issue affects A…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-49640
|
2024-11-1 01:04 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|