2431
|
- |
|
-
|
-
|
Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-4464
|
2024-12-18 15:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2432
|
- |
|
-
|
-
|
Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker…
|
-
|
CVE-2024-21547
|
2024-12-18 15:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2433
|
- |
|
-
|
-
|
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extensi…
|
-
|
CVE-2024-21546
|
2024-12-18 15:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2434
|
- |
|
-
|
-
|
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is correct,…
|
-
|
CVE-2024-56170
|
2024-12-18 14:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2435
|
- |
|
-
|
-
|
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are supposed to maintain a backup cache of the remote RPKI data. This can be employ…
|
-
|
CVE-2024-56169
|
2024-12-18 14:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2436
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were protected, not streams created by…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-12698
|
2024-12-18 14:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2437
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all…
|
CWE-862
Missing Authorization
|
CVE-2024-12596
|
2024-12-18 13:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2438
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_player_html' shortcode in all versions up to, …
|
CWE-79
Cross-site Scripting
|
CVE-2024-12449
|
2024-12-18 13:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2439
|
8.1 |
HIGH
Network
|
-
|
-
|
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_ke…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2024-12432
|
2024-12-18 13:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2440
|
8.8 |
HIGH
Network
|
-
|
-
|
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not prop…
|
CWE-862
Missing Authorization
|
CVE-2024-12259
|
2024-12-18 13:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|