|
314421
|
5.4 |
MEDIUM
Network
|
yogeshojha
|
rengine
|
reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when scanning a…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43381
|
2024-09-11 22:02 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314422
|
9.8 |
CRITICAL
Network
|
h3c
|
magic_b1st_firmware
|
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-42638
|
2024-09-11 21:53 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314423
|
7.5 |
HIGH
Network
|
google
|
android
|
In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution pri…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-34727
|
2024-09-11 21:43 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314424
|
8.2 |
HIGH
Network
|
xpdfreader
|
xpdf
|
In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read fro…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-7868
|
2024-09-11 21:40 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314425
|
8.8 |
HIGH
Network
|
xyzscripts
|
insert_php_code_snippet
|
Cross-Site Request Forgery (CSRF) vulnerability in xyzscripts.Com Insert PHP Code Snippet.This issue affects Insert PHP Code Snippet: from n/a through 1.3.6.
|
CWE-352
Origin Validation Error
|
CVE-2024-43275
|
2024-09-11 21:33 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314426
|
- |
|
-
|
-
|
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE).
This issue affects: Comm…
|
-
|
CVE-2024-43690
|
2024-09-11 14:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314427
|
- |
|
-
|
-
|
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious …
|
-
|
CVE-2024-21529
|
2024-09-11 14:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314428
|
- |
|
-
|
-
|
Affected versions of Octopus Server had a weak content security policy.
|
-
|
CVE-2024-1656
|
2024-09-11 14:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314429
|
- |
|
-
|
-
|
Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows an attacker with physical access to Controller wiring to instigate a reboot lea…
|
-
|
CVE-2024-39808
|
2024-09-11 13:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314430
|
- |
|
-
|
-
|
Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authorised and authenticated operator to reboot the Controller, caus…
|
-
|
CVE-2024-24972
|
2024-09-11 13:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|