|
313751
|
4.3 |
MEDIUM
Network
|
istyle
|
\@cosme
|
Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to …
|
NVD-CWE-noinfo
|
CVE-2024-45203
|
2024-09-16 22:27 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313752
|
9.8 |
CRITICAL
Network
|
project_team
|
tmall_demo
|
A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argu…
|
CWE-89
SQL Injection
|
CVE-2024-8568
|
2024-09-16 22:22 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313753
|
4.8 |
MEDIUM
Network
|
anujk305
|
bus_pass_management_system
|
phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44798
|
2024-09-16 22:19 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313754
|
7.8 |
HIGH
Local
|
adobe
|
illustrator
|
Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user.…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2024-41857
|
2024-09-16 22:18 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313755
|
5.5 |
MEDIUM
Local
|
adobe
|
premiere_pro
|
Premiere Pro versions 24.5, 23.6.8 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypas…
|
CWE-416
Use After Free
|
CVE-2024-39385
|
2024-09-16 22:12 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313756
|
7.8 |
HIGH
Local
|
adobe
|
premiere_pro
|
Premiere Pro versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of t…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-39384
|
2024-09-16 22:01 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313757
|
7.8 |
HIGH
Local
|
qnap
|
qts quts_hero
|
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to execute commands via unspe…
|
CWE-78 CWE-77
OS Command Command Injection
|
CVE-2024-38641
|
2024-09-16 21:35 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313758
|
7.8 |
HIGH
Local
|
qnap
|
qumagie
|
An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unsp…
|
CWE-295
Improper Certificate Validation
|
CVE-2024-38642
|
2024-09-16 21:33 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313759
|
5.4 |
MEDIUM
Network
|
qnap
|
download_station
|
A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We ha…
|
CWE-79
Cross-site Scripting
|
CVE-2024-38640
|
2024-09-16 21:27 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313760
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
vsock: fix recursive ->recvmsg calls
After a vsock socket has been added to a BPF sockmap, its prot->recvmsg
has been replaced wi…
|
CWE-674
Uncontrolled Recursion
|
CVE-2024-44996
|
2024-09-16 21:21 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|