2151
|
- |
|
-
|
-
|
A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.1. Affected is an unknown function of the file /admin/store.php. The manipulation of the argument tag leads to cross si…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-12844
|
2024-12-21 06:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2152
|
- |
|
-
|
-
|
A vulnerability was found in Emlog Pro up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the file /admin/plugin.php. The manipulation of the argument filter…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-12843
|
2024-12-21 06:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2153
|
- |
|
-
|
-
|
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organizati…
|
CWE-287 CWE-284 CWE-285 CWE-269
Improper Authentication Improper Access Control Improper Authorization Improper Privilege Management
|
CVE-2024-56335
|
2024-12-21 06:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2154
|
- |
|
-
|
-
|
Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with client assets such a…
|
-
|
CVE-2024-56159
|
2024-12-21 06:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2155
|
- |
|
-
|
-
|
pdftools is a high level tools to convert PDF files to ePUB formats. In versions up to and including 0.5.0 maliciously crafted epub files can cause a stack overflow leading to a crash. This issue has…
|
-
|
CVE-2024-56139
|
2024-12-21 06:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2156
|
- |
|
-
|
-
|
A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter…
|
-
|
CVE-2024-55496
|
2024-12-21 06:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2157
|
- |
|
-
|
-
|
Onyxia is a web app that aims at being the glue between multiple open source backend technologies to provide a state of art working environment for data scientists. This critical vulnerability allows…
|
CWE-94
Code Injection
|
CVE-2024-56333
|
2024-12-21 05:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2158
|
- |
|
-
|
-
|
Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacker to access sensitive local files on the server by exploiting the `file:///` pr…
|
CWE-22
Path Traversal
|
CVE-2024-56331
|
2024-12-21 05:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2159
|
- |
|
-
|
-
|
Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC) is not disabled. This would allow users within a container to access another c…
|
CWE-284
Improper Access Control
|
CVE-2024-56330
|
2024-12-21 05:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2160
|
- |
|
-
|
-
|
Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jetstream, with scaffolding that has support for Lara…
|
CWE-287
Improper Authentication
|
CVE-2024-56329
|
2024-12-21 05:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|