2421
|
- |
|
-
|
-
|
SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php.
|
-
|
CVE-2024-25325
|
2024-11-1 03:35 |
2024-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2422
|
- |
|
-
|
-
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 …
|
-
|
CVE-2024-23231
|
2024-11-1 03:35 |
2024-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2423
|
- |
|
-
|
-
|
ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/lib_termcap.c. NOTE: Multiple third parties have disputed this indicating upstream does not regard it as a security issue.
|
-
|
CVE-2023-45918
|
2024-11-1 03:35 |
2024-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2424
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
powerpc/pseries/iommu: IOMMU table is not initialized for kdump over SR-IOV
When kdump kernel tries to copy dump data over SR-IOV…
|
-
|
CVE-2024-26745
|
2024-11-1 03:35 |
2024-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2425
|
6.1 |
MEDIUM
Network
|
awplife
|
formula
|
The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'quality_customizer_notify_dismiss_action' AJAX action in all versions up to, and includi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5613
|
2024-11-1 03:31 |
2024-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2426
|
5.4 |
MEDIUM
Network
|
webfactoryltd
|
minimal_coming_soon_\&_maintenance_mode
|
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_aj…
|
CWE-862
Missing Authorization
|
CVE-2024-5087
|
2024-11-1 03:26 |
2024-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2427
|
7.8 |
HIGH
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
In the Linux kernel, the following vulnerability has been resolved:
parport: Proper fix for array out-of-bounds access
The recent fix for array out-of-bounds accesses replaced sprintf()
calls blind…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-50074
|
2024-11-1 03:23 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2428
|
4.3 |
MEDIUM
Network
|
webfactoryltd
|
wp_reset
|
The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes…
|
CWE-862
Missing Authorization
|
CVE-2024-4661
|
2024-11-1 03:21 |
2024-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2429
|
9.1 |
CRITICAL
Network
gaizhenbiao
|
chuanhuchatgpt
|
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files w…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2024-5823
|
2024-11-1 03:05 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2430
|
6.1 |
MEDIUM
Network
|
soft-master
|
affiliate_platform
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform allows Reflected XSS.This issue affects Affiliate Platfor…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49645
|
2024-11-1 02:59 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|