391
|
7.5 |
HIGH
Network
gaizhenbiao
|
chuanhuchatgpt
|
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a …
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-7807
|
2024-11-14 23:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
392
|
8.1 |
HIGH
Network
|
lunary
|
lunary
|
In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by manipulating the 'id' parameter in the request URL. …
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-7474
|
2024-11-14 23:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
393
|
5.9 |
MEDIUM
Network
|
mudler
|
localai
|
mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic…
Update
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-7010
|
2024-11-14 23:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
394
|
5.5 |
MEDIUM
Local
|
adobe
|
bridge
|
Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypa…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2024-45147
|
2024-11-14 22:58 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
395
|
6.8 |
MEDIUM
Adjacent
|
zyxel
|
gs1900-8_firmware gs1900-8hp_firmware gs1900-10hp_firmware gs1900-16_firmware gs1900-24_firmware gs1900-24e_firmware gs1900-24ep_firmware gs1900-24hpv2_firmware gs1900-48_firm…
|
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker wi…
Update
|
CWE-78
OS Command
|
CVE-2024-8881
|
2024-11-14 22:51 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
396
|
4.5 |
MEDIUM
Adjacent
|
zyxel
|
gs1900-8_firmware gs1900-8hp_firmware gs1900-10hp_firmware gs1900-16_firmware gs1900-24_firmware gs1900-24e_firmware gs1900-24ep_firmware gs1900-24hpv2_firmware gs1900-48_firm…
|
A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privi…
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-8882
|
2024-11-14 22:42 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
397
|
5.3 |
MEDIUM
Network
neomutt mutt redhat
|
neomutt mutt enterprise_linux
|
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original …
Update
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-49394
|
2024-11-14 22:38 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
398
|
5.3 |
MEDIUM
Network
neomutt mutt redhat
|
neomutt mutt enterprise_linux
|
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
Update
|
NVD-CWE-noinfo
|
CVE-2024-49395
|
2024-11-14 22:33 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
399
|
5.4 |
MEDIUM
Network
|
leevio
|
happy_addons_for_elementor
|
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-10538
|
2024-11-14 22:27 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
400
|
- |
|
-
|
-
|
An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious Ja…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-8648
|
2024-11-14 22:15 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|