|
312581
|
5.3 |
MEDIUM
Network
|
erudika
|
scoold
|
Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass …
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-50334
|
2024-11-9 04:51 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312582
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: wwan: fix global oob in wwan_rtnl_policy
The variable wwan_rtnl_link_ops assign a *bigger* maxtype which leads to
a global o…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-50128
|
2024-11-9 04:39 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312583
|
5.4 |
MEDIUM
Network
|
avecnous
|
event_post
|
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10186
|
2024-11-9 04:21 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312584
|
5.4 |
MEDIUM
Network
|
microfocus
|
imanager
|
Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3
|
CWE-79
Cross-site Scripting
|
CVE-2020-11859
|
2024-11-9 04:12 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312585
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Unregister redistributor for failed vCPU creation
Alex reports that syzkaller has managed to trigger a use-after-free…
|
CWE-416
Use After Free
|
CVE-2024-50114
|
2024-11-9 04:11 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312586
|
- |
|
-
|
-
|
A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with adminis…
|
-
|
CVE-2024-8810
|
2024-11-9 04:01 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312587
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the conte…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49524
|
2024-11-9 04:01 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312588
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable …
|
CWE-79
Cross-site Scripting
|
CVE-2024-49523
|
2024-11-9 04:01 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312589
|
- |
|
-
|
-
|
The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by…
|
-
|
CVE-2024-36062
|
2024-11-9 04:01 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312590
|
- |
|
-
|
-
|
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for business own…
|
-
|
CVE-2024-10824
|
2024-11-9 04:01 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|