|
312591
|
5.4 |
MEDIUM
Network
|
lopalopa
|
music_management_system
|
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitra…
|
CWE-79
Cross-site Scripting
|
CVE-2024-42790
|
2024-09-6 03:36 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312592
|
9.8 |
CRITICAL
Network
|
seacms
|
seacms
|
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
|
CWE-89
SQL Injection
|
CVE-2024-41444
|
2024-09-6 03:36 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312593
|
3.5 |
LOW
Network
|
lopalopa
|
music_management_system
|
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page.
|
CWE-352
Origin Validation Error
|
CVE-2024-42792
|
2024-09-6 03:35 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312594
|
7.5 |
HIGH
Network
|
netskope
|
netskope
|
Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, …
|
CWE-287
Improper Authentication
|
CVE-2024-7401
|
2024-09-6 03:34 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312595
|
9.8 |
CRITICAL
Network
|
ruoyi
|
ruoyi
|
RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.
|
CWE-89
SQL Injection
|
CVE-2024-42913
|
2024-09-6 03:31 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312596
|
9.8 |
CRITICAL
Network
|
skyss
|
arfa-cms
|
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.
|
CWE-89
SQL Injection
|
CVE-2024-45265
|
2024-09-6 03:30 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312597
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses
Currently, it's possible to pass in a modified…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-43910
|
2024-09-6 03:30 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312598
|
6.1 |
MEDIUM
Network
|
testlink
|
testlink
|
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.
|
CWE-79
Cross-site Scripting
|
CVE-2024-42906
|
2024-09-6 03:29 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312599
|
7.5 |
HIGH
Network
|
gl-inet
|
mt6000_firmware x3000_firmware xe3000_firmware a1300_firmware ax1800_firmware axt1800_firmware mt2500_firmware mt3000_firmware xe300_firmware x750_firmware sft1200_firmw…
|
A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports …
|
NVD-CWE-noinfo
|
CVE-2024-28077
|
2024-09-6 03:29 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312600
|
6.1 |
MEDIUM
Network
|
xiebruce
|
picuploader
|
A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted pay…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44794
|
2024-09-6 03:28 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|