671
|
- |
|
-
|
-
|
Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to byp…
|
CWE-22
Path Traversal
|
CVE-2024-11215
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
672
|
- |
|
-
|
-
|
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authe…
|
CWE-287
Improper Authentication
|
CVE-2024-11209
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
673
|
- |
|
-
|
-
|
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiratio…
|
CWE-613
Insufficient Session Expiration
|
CVE-2024-11208
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
674
|
8.8 |
HIGH
Network
|
-
|
-
|
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replac…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-10962
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
675
|
- |
|
-
|
-
|
An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious Ja…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8648
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
676
|
- |
|
-
|
-
|
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2024-7404
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
677
|
- |
|
-
|
-
|
A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirec…
|
CWE-601
Open Redirect
|
CVE-2024-11207
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
678
|
- |
|
-
|
-
|
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arb…
|
-
|
CVE-2024-10979
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
679
|
- |
|
-
|
-
|
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-…
|
-
|
CVE-2024-10977
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
680
|
- |
|
-
|
-
|
A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit …
|
-
|
CVE-2024-7730
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|