1241
|
- |
|
-
|
-
|
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to other servers as part of normal operation, and these resource owners can return la…
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2024-52791
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1242
|
- |
|
-
|
-
|
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private net…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-52602
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1243
|
- |
|
-
|
-
|
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Root" user from the org…
|
CWE-287 CWE-284 CWE-285 CWE-269 CWE-272
Improper Authentication Improper Access Control Improper Authorization Improper Privilege Management Least Privilege Violation
|
CVE-2024-55954
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1244
|
- |
|
-
|
-
|
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded disk consumption, where an unauthenticated adversary…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-36403
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1245
|
- |
|
-
|
-
|
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to trigger a download an…
|
CWE-287
Improper Authentication
|
CVE-2024-36402
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1246
|
- |
|
-
|
-
|
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.
|
-
|
CVE-2024-57684
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1247
|
- |
|
-
|
-
|
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creatin…
|
-
|
CVE-2025-20630
|
2025-01-17 04:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1248
|
- |
|
-
|
-
|
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allo…
|
-
|
CVE-2025-20621
|
2025-01-17 04:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1249
|
- |
|
-
|
-
|
An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST req…
|
-
|
CVE-2024-57683
|
2025-01-17 04:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1250
|
- |
|
-
|
-
|
An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST req…
|
-
|
CVE-2024-57682
|
2025-01-17 04:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|