|
312471
|
8.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing.
Malicious software running in a guest VM that exposes virtio_scsi c…
|
CWE-416
Use After Free
|
CVE-2024-45063
|
2024-09-7 02:35 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312472
|
- |
|
-
|
-
|
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
|
-
|
CVE-2024-42919
|
2024-09-7 02:35 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312473
|
- |
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
|
-
|
CVE-2024-42557
|
2024-09-7 02:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312474
|
7.5 |
HIGH
Network
|
rust-bitcoin
|
miniscript
|
The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44073
|
2024-09-7 02:35 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312475
|
- |
|
-
|
-
|
The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include…
|
-
|
CVE-2024-6459
|
2024-09-7 02:35 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312476
|
9.8 |
CRITICAL
Network
|
totolink
|
lr350_firmware
|
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-…
|
NVD-CWE-noinfo
|
CVE-2024-42967
|
2024-09-7 02:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312477
|
9.8 |
CRITICAL
Network
|
tenda
|
fh1201_firmware
|
An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.
|
NVD-CWE-noinfo
|
CVE-2024-42947
|
2024-09-7 02:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312478
|
7.8 |
HIGH
Local
|
cysoft168
|
super_easy_enterprise_management_system
|
SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.
|
CWE-89
SQL Injection
|
CVE-2024-42679
|
2024-09-7 02:35 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312479
|
4.8 |
MEDIUM
Network
|
micro.company
|
collect.chat
|
The Chatbot for WordPress by Collect.chat ?? WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Sit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6498
|
2024-09-7 02:35 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312480
|
8.6 |
HIGH
Network
|
rocket.chat
|
rocket.chat
|
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-39713
|
2024-09-7 02:35 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|