|
312491
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-300_firmware
|
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-41616
|
2024-08-8 05:54 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312492
|
6.1 |
MEDIUM
Network
|
phpgurukul
|
tourism_management_system
|
A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted…
|
CWE-79
Cross-site Scripting
|
CVE-2024-41333
|
2024-08-8 05:54 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312493
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2024-6988
|
2024-08-8 05:51 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312494
|
4.7 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of…
|
NVD-CWE-noinfo
|
CVE-2024-6995
|
2024-08-8 05:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312495
|
- |
|
-
|
-
|
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
|
-
|
CVE-2024-41264
|
2024-08-8 05:35 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312496
|
- |
|
-
|
-
|
The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks
|
-
|
CVE-2024-2843
|
2024-08-8 05:35 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312497
|
- |
|
abarcar
|
abarcar_realty_portal
|
Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to sl…
|
CWE-89
SQL Injection
|
CVE-2006-5840
|
2024-08-8 05:15 |
2006-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312498
|
- |
|
marc_cagninacci
|
mclinkscounter
|
Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2)…
|
CWE-94
Code Injection
|
CVE-2006-4863
|
2024-08-8 05:15 |
2006-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312499
|
- |
|
hitweb
|
hitweb
|
Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php,…
|
NVD-CWE-Other
|
CVE-2006-4848
|
2024-08-8 05:15 |
2006-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312500
|
- |
|
phpopenchat
|
phpopenchat
|
PHP remote file inclusion vulnerability in contrib/yabbse/poc.php in phpopenchat before 3.0.2 allows remote attackers to execute arbitrary PHP code via the sourcedir parameter. NOTE: this issue was …
|
NVD-CWE-Other
|
CVE-2006-4677
|
2024-08-8 05:15 |
2006-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|