|
313001
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The manipulation of the a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8294
|
2024-08-31 00:38 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313002
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbanner-create. The mani…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8295
|
2024-08-31 00:37 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313003
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation of the argument Use…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8296
|
2024-08-31 00:36 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313004
|
7.8 |
HIGH
Local
|
aertherwide
|
exiftags
|
Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-42851
|
2024-08-31 00:30 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313005
|
7.5 |
HIGH
Network
|
kitsada8621
|
digital_library_management_system
|
A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2024-8297
|
2024-08-31 00:28 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313006
|
9.8 |
CRITICAL
Network
|
gitapp
|
dingfanzu
|
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /aj…
|
CWE-89
SQL Injection
|
CVE-2024-8301
|
2024-08-31 00:24 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313007
|
4.8 |
MEDIUM
Adjacent
|
teldat
|
rs123_firmware rs123w_firmware
|
Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.
|
CWE-79
Cross-site Scripting
|
CVE-2022-39996
|
2024-08-31 00:17 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313008
|
4.3 |
MEDIUM
Network
|
smashballoon
|
reviews_feed
|
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i…
|
CWE-352
Origin Validation Error
|
CVE-2024-8200
|
2024-08-31 00:08 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313009
|
4.3 |
MEDIUM
Network
|
smashballoon
|
reviews_feed
|
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa…
|
CWE-862
Missing Authorization
|
CVE-2024-8199
|
2024-08-31 00:04 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313010
|
8.8 |
HIGH
Network
|
skyss
|
arfa-cms
|
A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.
|
CWE-352
Origin Validation Error
|
CVE-2024-45264
|
2024-08-31 00:02 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|