|
313551
|
7.5 |
HIGH
Network
|
ibm
|
common_licensing
|
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.
|
CWE-521
Weak Password Requirements
|
CVE-2024-40697
|
2024-08-22 22:27 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313552
|
2.7 |
LOW
Network
|
mainwww
|
mwcms
|
A vulnerability was found in Fujian mwcms 1.0.0. It has been rated as critical. Affected by this issue is the function uploadimage of the file /uploadfile.html. The manipulation of the argument upfil…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7706
|
2024-08-22 22:26 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313553
|
9.8 |
CRITICAL
Network
|
tenda
|
fh1206_firmware
|
A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function formSafeEmailFilter of the file /goform/SafeEmailFilter of the component HTTP …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7707
|
2024-08-22 22:23 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313554
|
- |
|
-
|
-
|
Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.
|
CWE-862
Missing Authorization
|
CVE-2024-43331
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313555
|
- |
|
-
|
-
|
Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-39576
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313556
|
- |
|
-
|
-
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and…
|
-
|
CVE-2024-20486
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313557
|
- |
|
-
|
-
|
Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks.
These vulnerabilities are due…
|
-
|
CVE-2024-20417
|
2024-08-22 21:48 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313558
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2022-48900
|
2024-08-22 17:15 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313559
|
7.8 |
HIGH
Local
|
kingsoft
|
wps_office
|
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows libr…
|
CWE-22
Path Traversal
|
CVE-2024-7263
|
2024-08-22 15:15 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313560
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-42143
|
2024-08-22 09:15 |
2024-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|