|
312701
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: prevent copying too big compressed lzo segment
Compressed length can be corrupted to be a lot larger than memory
we have a…
|
CWE-787
Out-of-bounds Write
|
CVE-2022-48923
|
2024-09-12 21:50 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312702
|
7.2 |
HIGH
Network
|
lifterlms
|
lifterlms
|
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in all versions up to, and including, 7.7.5 due to …
|
CWE-89
SQL Injection
|
CVE-2024-7349
|
2024-09-12 21:43 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312703
|
9.8 |
CRITICAL
Network
|
plechevandrey
|
wp-recall
|
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plu…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8292
|
2024-09-12 21:37 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312704
|
- |
|
-
|
-
|
A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDat…
|
CWE-89
SQL Injection
|
CVE-2024-8705
|
2024-09-12 21:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312705
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.ad…
|
CWE-22
Path Traversal
|
CVE-2024-8694
|
2024-09-12 21:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312706
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is some unknown functionality of the component dhcpcd Command Handler. The manipula…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8693
|
2024-09-12 21:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312707
|
- |
|
-
|
-
|
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."
|
-
|
CVE-2024-44541
|
2024-09-12 21:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312708
|
- |
|
-
|
-
|
A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles.
|
-
|
CVE-2024-8689
|
2024-09-12 21:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312709
|
- |
|
-
|
-
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server log.This is…
|
-
|
CVE-2024-8097
|
2024-09-12 21:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312710
|
- |
|
-
|
-
|
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.
|
-
|
CVE-2024-44577
|
2024-09-12 21:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|