|
312371
|
9.8 |
CRITICAL
Network
|
seacms
|
seacms
|
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
|
CWE-89
SQL Injection
|
CVE-2024-44921
|
2024-09-5 00:00 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312372
|
6.1 |
MEDIUM
Network
|
seacms
|
seacms
|
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the si…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44920
|
2024-09-4 23:59 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312373
|
9.8 |
CRITICAL
Network
|
rems
|
contact_manager_with_export_to_vcf
|
A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing of the file /endpoint/delete-account.php …
|
CWE-89
SQL Injection
|
CVE-2024-8380
|
2024-09-4 23:58 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312374
|
5.4 |
MEDIUM
Network
|
3ds
|
3dexperience_enovia
|
A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8004
|
2024-09-4 23:56 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312375
|
5.4 |
MEDIUM
Network
|
3ds
|
3dexperience
|
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7938
|
2024-09-4 23:53 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312376
|
6.1 |
MEDIUM
Network
|
checkmk
|
checkmk
|
Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.
|
CWE-79
Cross-site Scripting
|
CVE-2024-38858
|
2024-09-4 23:39 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312377
|
6.5 |
MEDIUM
Network
|
hashicorp
|
vault
|
Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors,…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-8365
|
2024-09-4 23:37 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312378
|
- |
|
-
|
-
|
Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-8362
|
2024-09-4 23:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312379
|
- |
|
-
|
-
|
Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-7970
|
2024-09-4 23:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312380
|
- |
|
-
|
-
|
A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from improper sanitization of user input passed to the "position" GE…
|
-
|
CVE-2024-44809
|
2024-09-4 23:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|