771
|
9.8 |
CRITICAL
Network
codezips
|
online_institute_management_system
|
A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /pages/save_user.php. The manipulation of the argume…
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-10764
|
2024-11-6 23:44 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
772
|
7.1 |
HIGH
Local
|
apple
|
iphone_os ipados visionos tvos
|
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, tvOS 18.1. Restoring a maliciously crafted ba…
Update
|
CWE-59
Link Following
|
CVE-2024-44258
|
2024-11-6 23:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
773
|
8.8 |
HIGH
Network
|
combodo
|
itop
|
Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgra…
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-31998
|
2024-11-6 23:31 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
774
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can be performed when importing this content. This iss…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-31448
|
2024-11-6 23:31 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
775
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9,…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2023-34445
|
2024-11-6 23:29 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
776
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2023-34444
|
2024-11-6 23:28 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
777
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of script tags. This has been fixed in ver…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2023-34443
|
2024-11-6 23:25 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
778
|
4.4 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to…
Update
|
CWE-22
Path Traversal
|
CVE-2024-9675
|
2024-11-6 19:15 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
779
|
7.5 |
HIGH
Network
libtiff redhat
|
libtiff enterprise_linux enterprise_linux_server_aus enterprise_linux_for_power_little_endian_eus enterprise_linux_for_arm_64
|
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap sp…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-7006
|
2024-11-6 19:15 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
780
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field fro…
Update
|
CWE-200
Information Exposure
|
CVE-2024-8553
|
2024-11-6 18:15 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|