2371
|
8.8 |
HIGH
Network
|
-
|
-
|
The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted request…
|
CWE-302
Authentication Bypass by Assumed-Immutable Data
|
CVE-2024-12838
|
2024-12-31 11:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2372
|
- |
|
-
|
-
|
An issue exists in SoftIron HyperCloud
where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backend software-defined…
|
-
|
CVE-2024-13058
|
2024-12-31 07:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2373
|
- |
|
-
|
-
|
Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker m…
|
CWE-59
Link Following
|
CVE-2024-12753
|
2024-12-31 06:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2374
|
- |
|
-
|
-
|
Foxit PDF Reader AcroForm Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. Us…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2024-12752
|
2024-12-31 06:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2375
|
- |
|
-
|
-
|
Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. U…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-12751
|
2024-12-31 06:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2376
|
- |
|
-
|
-
|
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-11946
|
2024-12-31 06:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2377
|
- |
|
-
|
-
|
iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat…
|
CWE-22
Path Traversal
|
CVE-2024-11944
|
2024-12-31 06:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2378
|
- |
|
-
|
-
|
Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.
|
CWE-89
SQL Injection
|
CVE-2024-56801
|
2024-12-31 04:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2379
|
- |
|
-
|
-
|
Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions prior to 1.1.1 contain a server-side request forgery (SSRF) vulnerability. The sc…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-56800
|
2024-12-31 04:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2380
|
- |
|
-
|
-
|
Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when the…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-56799
|
2024-12-31 04:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|