581
|
- |
|
-
|
-
|
Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NE…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-10456
|
2024-10-31 03:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
582
|
- |
|
-
|
-
|
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configura…
Update
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-8036
|
2024-10-31 03:15 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
583
|
7.1 |
HIGH
Local
|
apple
|
iphone_os ipados visionos tvos
|
A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, tvOS 18.1. Restoring a maliciously crafted backup…
Update
|
NVD-CWE-noinfo
|
CVE-2024-44252
|
2024-10-31 03:11 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
584
|
9.8 |
CRITICAL
Network
codezips
|
pet_shop_management_system
|
A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an unknown function of the file /deletebird.php. The manipulation of the argument …
Update
|
CWE-89
SQL Injection
|
CVE-2024-10431
|
2024-10-31 03:10 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
585
|
7.5 |
HIGH
Network
useragent_project
|
useragent
|
Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of…
Update
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2020-26311
|
2024-10-31 03:07 |
2024-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
586
|
9.8 |
CRITICAL
Network
digitalzoomstudio
|
zoomsounds
|
The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possibl…
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-4449
|
2024-10-31 03:06 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
587
|
6.1 |
MEDIUM
Network
|
openrefine
|
openrefine
|
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `<script>` tag …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-47878
|
2024-10-31 03:01 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
588
|
5.5 |
MEDIUM
Local
|
apple
|
macos iphone_os ipados watchos visionos tvos
|
The issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, vision…
Update
|
NVD-CWE-noinfo
|
CVE-2024-44302
|
2024-10-31 02:49 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
589
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious application may be able to modify protected parts of the file system.
Update
|
NVD-CWE-noinfo
|
CVE-2024-44247
|
2024-10-31 02:49 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
590
|
8.8 |
HIGH
Network
|
pickplugins
|
post_grid
|
The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack…
Update
|
CWE-89
SQL Injection
|
CVE-2021-4450
|
2024-10-31 02:47 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|