1661
|
- |
|
-
|
-
|
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. Affected is the function fln_update of the file /_parse/_all_edits.php. The manipulation of the argument fn…
|
-
|
CVE-2024-12967
|
2024-12-31 00:15 |
2024-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1662
|
7.2 |
HIGH
Network
|
-
|
-
|
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this…
|
CWE-78
OS Command
|
CVE-2024-54181
|
2024-12-30 23:15 |
2024-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1663
|
- |
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat, as of commit e208d5677c6837d590b81cb03847c0…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-10044
|
2024-12-30 21:15 |
2024-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1664
|
- |
|
-
|
-
|
Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without a…
|
-
|
CVE-2024-12993
|
2024-12-30 20:15 |
2024-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1665
|
- |
|
-
|
-
|
Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
|
CWE-89
SQL Injection
|
CVE-2024-47926
|
2024-12-30 19:15 |
2024-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1666
|
- |
|
-
|
-
|
Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
|
CWE-79
Cross-site Scripting
|
CVE-2024-47925
|
2024-12-30 19:15 |
2024-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1667
|
- |
|
-
|
-
|
Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
|
CWE-79
Cross-site Scripting
|
CVE-2024-47924
|
2024-12-30 19:15 |
2024-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1668
|
- |
|
-
|
-
|
Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
|
CWE-200
Information Exposure
|
CVE-2024-47923
|
2024-12-30 19:15 |
2024-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1669
|
- |
|
-
|
-
|
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
|
CWE-200
Information Exposure
|
CVE-2024-47922
|
2024-12-30 19:15 |
2024-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1670
|
- |
|
-
|
-
|
Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2024-47921
|
2024-12-30 19:15 |
2024-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|