|
312421
|
6.6 |
MEDIUM
Network
|
-
|
-
|
The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions up to, and including, 0.9.7. Th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7620
|
2024-09-9 22:03 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312422
|
- |
|
-
|
-
|
A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Comman…
|
CWE-94
Code Injection
|
CVE-2024-8523
|
2024-09-9 22:03 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312423
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument man…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8521
|
2024-09-9 22:03 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312424
|
- |
|
-
|
-
|
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affe…
|
-
|
CVE-2024-7652
|
2024-09-9 22:03 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312425
|
7.8 |
HIGH
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
|
CWE-416
Use After Free
|
CVE-2024-41160
|
2024-09-9 21:21 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312426
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-42334
|
2024-09-8 21:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312427
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to truncate preallocated blocks in f2fs_file_open()
chenyuwen reports a f2fs bug as below:
Unable to handle kernel NUL…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-43859
|
2024-09-8 17:15 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312428
|
9.8 |
CRITICAL
Network
|
ibm
|
security_directory_integrator security_verify_directory_integrator
|
IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a sign…
|
NVD-CWE-noinfo
|
CVE-2022-33162
|
2024-09-7 22:15 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312429
|
9.8 |
CRITICAL
Network
|
oretnom23
|
clinic\'s_patient_management_system
|
A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is the function patient_name of the file patients.php…
|
CWE-89
SQL Injection
|
CVE-2024-7454
|
2024-09-7 21:56 |
2024-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312430
|
9.8 |
CRITICAL
Network
|
onesoftnet
|
sudobot
|
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of …
|
CWE-862
Missing Authorization
|
CVE-2024-45307
|
2024-09-7 10:34 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|