|
312431
|
6.1 |
MEDIUM
Network
|
xiebruce
|
picuploader
|
A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44796
|
2024-09-7 08:35 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312432
|
8.8 |
HIGH
Network
|
roxy-wi
|
roxy-wi
|
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code…
|
CWE-78
OS Command
|
CVE-2024-43804
|
2024-09-7 07:57 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312433
|
8.1 |
HIGH
Network
|
getkirby
|
kirby
|
Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for creating and de…
|
CWE-863
Incorrect Authorization
|
CVE-2024-41964
|
2024-09-7 07:56 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312434
|
5.4 |
MEDIUM
Network
|
seacms
|
seacms
|
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad descript…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44919
|
2024-09-7 07:54 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312435
|
9.8 |
CRITICAL
Network
|
deltaww
|
dtn_soft
|
Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-8255
|
2024-09-7 07:53 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312436
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and le…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-5991
|
2024-09-7 07:51 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312437
|
9.8 |
CRITICAL
Network
|
hp
|
security_manager
|
HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.
|
NVD-CWE-noinfo
|
CVE-2024-7720
|
2024-09-7 07:33 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312438
|
6.1 |
MEDIUM
Network
|
gazelle_project
|
gazelle
|
A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inj…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44797
|
2024-09-7 07:27 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312439
|
6.5 |
MEDIUM
Network
|
beikeshop
|
beikeshop
|
A vulnerability, which was classified as problematic, was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function exportZip of the file /admin/file_manager/expo…
|
CWE-22
Path Traversal
|
CVE-2024-8165
|
2024-09-7 07:20 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312440
|
8.8 |
HIGH
Network
|
beikeshop
|
beikeshop
|
A vulnerability, which was classified as critical, has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function rename of the file /Admin/Http/…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8164
|
2024-09-7 07:19 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|