|
313221
|
- |
|
-
|
-
|
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-8904
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313222
|
- |
|
-
|
-
|
Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages r…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-46982
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313223
|
- |
|
-
|
-
|
Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` output format. …
|
CWE-79
Cross-site Scripting
|
CVE-2024-45812
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313224
|
- |
|
-
|
-
|
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2024-45811
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313225
|
- |
|
-
|
-
|
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The `arduino-esp32` CI is vulnerable to multiple Poisoned Pipeline Execution (PPE…
|
CWE-94 CWE-20 CWE-78
Code Injection Improper Input Validation OS Command
|
CVE-2024-45798
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313226
|
- |
|
-
|
-
|
Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a …
|
-
|
CVE-2024-42503
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313227
|
- |
|
-
|
-
|
Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underly…
|
-
|
CVE-2024-42502
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313228
|
- |
|
-
|
-
|
An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system…
|
-
|
CVE-2024-42501
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313229
|
- |
|
-
|
-
|
A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead to a Denial of Service (DoS). The API used for LLM-base…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-8939
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313230
|
- |
|
-
|
-
|
A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.
|
CWE-617
Reachable Assertion
|
CVE-2024-8768
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|