1061
|
- |
|
-
|
-
|
Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice intr…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-56362
|
2024-12-24 03:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1062
|
- |
|
-
|
-
|
An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.
|
-
|
CVE-2024-56084
|
2024-12-24 03:15 |
2024-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1063
|
- |
|
-
|
-
|
SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, when calling the extended toHTMLEx method, it is possible to execute arbitrary J…
|
CWE-79
Cross-site Scripting
|
CVE-2024-56364
|
2024-12-24 01:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1064
|
- |
|
-
|
-
|
Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code which suffered a command injection due the usage of `rz_core_cmdf` to invoke th…
|
CWE-78
OS Command
|
CVE-2024-53256
|
2024-12-24 01:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1065
|
- |
|
-
|
-
|
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute a…
|
CWE-89 CWE-285
SQL Injection Improper Authorization
|
CVE-2024-45387
|
2024-12-24 01:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1066
|
- |
|
-
|
-
|
Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2024-55539
|
2024-12-23 23:15 |
2024-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1067
|
- |
|
-
|
-
|
Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges, execute arbitrary …
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-12903
|
2024-12-23 22:15 |
2024-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1068
|
8.4 |
HIGH
Local
|
-
|
-
|
ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows OS of the product contains high-privilege service accounts. If these accounts …
|
CWE-1392
Use of Default Credentials
|
CVE-2024-12902
|
2024-12-23 20:15 |
2024-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1069
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and including, 1.6.46 due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11230
|
2024-12-23 14:15 |
2024-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1070
|
- |
|
-
|
-
|
A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the component API Endpoint…
|
CWE-285 CWE-266
Improper Authorization Incorrect Privilege Assignment
|
CVE-2024-12901
|
2024-12-23 11:15 |
2024-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|