2411
|
- |
|
-
|
-
|
The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via three fields of the configuration menu for ntpserver0, ntpser…
|
-
|
CVE-2020-8007
|
2024-11-8 14:15 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2412
|
- |
|
-
|
-
|
Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with remote access could potentially …
|
CWE-200
Information Exposure
|
CVE-2024-48011
|
2024-11-8 12:15 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2413
|
- |
|
-
|
-
|
Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this vulnera…
|
CWE-284
Improper Access Control
|
CVE-2024-48010
|
2024-11-8 12:15 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2414
|
- |
|
-
|
-
|
Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially expl…
|
-
|
CVE-2024-45759
|
2024-11-8 12:15 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2415
|
- |
|
-
|
-
|
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstat…
|
-
|
CVE-2024-51567
|
2024-11-8 11:00 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2416
|
5.5 |
MEDIUM
Local
|
gpac debian
|
gpac debian_linux
|
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-4043
|
2024-11-8 11:00 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2417
|
9.8 |
CRITICAL
Network
nazgul
|
nostromo_nhttpd
|
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
|
CWE-22
Path Traversal
|
CVE-2019-16278
|
2024-11-8 11:00 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2418
|
- |
|
-
|
-
|
Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.
This issue affects EP…
|
-
|
CVE-2024-8424
|
2024-11-8 09:15 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2419
|
- |
|
-
|
-
|
changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attacker being able to read any file on the system. This…
|
CWE-22
Path Traversal
|
CVE-2024-51998
|
2024-11-8 09:15 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2420
|
- |
|
-
|
-
|
Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different us…
|
CWE-270
Privilege Context Switching Error
|
CVE-2024-51987
|
2024-11-8 09:15 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|