|
312041
|
9.8 |
CRITICAL
Network
|
geeeeeeeek
|
dingfanzu
|
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax/chpwd.…
|
CWE-89
SQL Injection
|
CVE-2024-8302
|
2024-09-20 06:55 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312042
|
9.8 |
CRITICAL
Network
|
stylemixthemes
|
cost_calculator_builder
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Bu…
|
CWE-89
SQL Injection
|
CVE-2024-43144
|
2024-09-20 06:47 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312043
|
9.8 |
CRITICAL
Network
|
templateinvaders
|
ti_woocommerce_wishlist
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce W…
|
CWE-89
SQL Injection
|
CVE-2024-43917
|
2024-09-20 06:46 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312044
|
9.8 |
CRITICAL
Network
|
nitropack
|
nitropack
|
Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.
|
CWE-94
Code Injection
|
CVE-2024-43922
|
2024-09-20 06:44 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312045
|
8.8 |
HIGH
Adjacent
|
dlink
|
covr-x1870_firmware dir-x4860_firmware
|
Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded…
|
CWE-912
Hidden Functionality
|
CVE-2024-45696
|
2024-09-20 06:42 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312046
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-x4860_firmware
|
Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS comm…
|
CWE-912
Hidden Functionality
|
CVE-2024-45697
|
2024-09-20 06:40 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312047
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluck
|
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2024-43042
|
2024-09-20 06:01 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312048
|
8.8 |
HIGH
Network
|
nuxt
|
nuxt
|
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an…
|
CWE-94
Code Injection
|
CVE-2024-34344
|
2024-09-20 05:58 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312049
|
7.5 |
HIGH
Network
|
nuxt
|
nuxt
|
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon lookup. This endpoint is at `/api/_nuxt_…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-42352
|
2024-09-20 05:55 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312050
|
7.8 |
HIGH
Local
|
mongodb
|
mongodb c_driver php_driver
|
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing…
|
NVD-CWE-noinfo
|
CVE-2024-7553
|
2024-09-20 05:46 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|