|
313171
|
- |
|
-
|
-
|
This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially leading …
|
-
|
CVE-2024-33657
|
2024-08-22 02:24 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313172
|
- |
|
-
|
-
|
The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escalation, arbitrary code execution, and bypassing OS s…
|
-
|
CVE-2024-33656
|
2024-08-22 02:24 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313173
|
- |
|
-
|
-
|
A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could all…
|
-
|
CVE-2024-20375
|
2024-08-22 02:24 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313174
|
9.8 |
CRITICAL
Network
|
arajajyothibabu
|
school_management_system
|
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.
|
CWE-89
SQL Injection
|
CVE-2024-42572
|
2024-08-22 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313175
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.
|
-
|
CVE-2024-42563
|
2024-08-22 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313176
|
- |
|
-
|
-
|
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.
|
-
|
CVE-2024-42556
|
2024-08-22 01:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313177
|
9.0 |
CRITICAL
Network
|
typecho
|
typecho
|
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2024-35540
|
2024-08-22 01:05 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313178
|
8.6 |
HIGH
Local
|
scilico
|
i-librarian
|
Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component.
|
CWE-79
Cross-site Scripting
|
CVE-2024-40500
|
2024-08-22 01:05 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313179
|
5.3 |
MEDIUM
Network
|
matrix
|
javascript_sdk
|
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's g…
|
CWE-674
Uncontrolled Recursion
|
CVE-2024-42369
|
2024-08-22 01:01 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313180
|
8.8 |
HIGH
Network
|
projectcapsule
|
capsule
|
Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e.,…
|
CWE-863
Incorrect Authorization
|
CVE-2024-39690
|
2024-08-22 01:01 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|