|
312091
|
- |
|
-
|
-
|
In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of privilege with no additional execution privileges n…
|
-
|
CVE-2024-40650
|
2024-09-12 23:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312092
|
- |
|
-
|
-
|
In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution pri…
|
-
|
CVE-2024-23716
|
2024-09-12 23:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312093
|
- |
|
-
|
-
|
An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell comma…
|
-
|
CVE-2024-8504
|
2024-09-12 23:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312094
|
- |
|
-
|
-
|
Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo.
|
-
|
CVE-2024-43040
|
2024-09-12 23:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312095
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fixed bug on error when unloading amdgpu
Fixed bug on error when unloading amdgpu.
The error message is as follows:
…
|
NVD-CWE-noinfo
|
CVE-2023-52912
|
2024-09-12 23:35 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312096
|
9.0 |
CRITICAL
Network
|
beckhoff
|
twincat\/bsd ipc_diagnostics_package
|
The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.
|
CWE-79
Cross-site Scripting
|
CVE-2024-41174
|
2024-09-12 23:33 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312097
|
5.4 |
MEDIUM
Network
|
ankitpokhrel
|
dynamic_featured_image
|
The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ parameter in all versions up to, and including, 3.7.0 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6929
|
2024-09-12 23:32 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312098
|
5.3 |
MEDIUM
Network
|
msoftplugins
|
security_antivirus_firewall
|
The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5. This is due to insufficient restrictions on where the IP A…
|
NVD-CWE-Other
|
CVE-2022-4529
|
2024-09-12 23:29 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312099
|
5.5 |
MEDIUM
Local
|
beckhoff
|
ipc_diagnostics_package twincat\/bsd
|
The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-41175
|
2024-09-12 23:25 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312100
|
4.3 |
MEDIUM
Network
|
helloasso
|
helloasso
|
The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ha_ajax' function in all versions up to, and including, 1.1.10. This ma…
|
CWE-862
Missing Authorization
|
CVE-2024-7605
|
2024-09-12 23:24 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|