1621
|
- |
|
-
|
-
|
Path Traversal: '.../...//' vulnerability in Themewinter Eventin allows Path Traversal.This issue affects Eventin: from n/a through 4.0.7.
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2024-56213
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1622
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DeluxeThemes Userpro.This issue affects Userpro: from n/a through 5.1.9.
|
CWE-89
SQL Injection
|
CVE-2024-56212
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1623
|
- |
|
-
|
-
|
Missing Authorization vulnerability in DeluxeThemes Userpro.This issue affects Userpro: from n/a through 5.1.9.
|
CWE-862
Missing Authorization
|
CVE-2024-56211
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1624
|
- |
|
-
|
-
|
Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for tr…
|
-
|
CVE-2024-49422
|
2024-12-31 18:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1625
|
- |
|
-
|
-
|
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plu…
|
-
|
CVE-2024-11972
|
2024-12-31 15:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1626
|
7.6 |
HIGH
Network
|
-
|
-
|
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod.…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-45497
|
2024-12-31 12:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1627
|
8.8 |
HIGH
Network
|
-
|
-
|
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access ce…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-13040
|
2024-12-31 11:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1628
|
8.8 |
HIGH
Network
|
-
|
-
|
The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed …
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2024-12839
|
2024-12-31 11:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1629
|
8.8 |
HIGH
Network
|
-
|
-
|
The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted request…
|
CWE-302
Authentication Bypass by Assumed-Immutable Data
|
CVE-2024-12838
|
2024-12-31 11:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1630
|
- |
|
-
|
-
|
An issue exists in SoftIron HyperCloud
where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backend software-defined…
|
-
|
CVE-2024-13058
|
2024-12-31 07:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|