|
312311
|
5.3 |
MEDIUM
Network
|
fogproject
|
fogproject
|
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via logs stored directly on the root of the web server. F…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-42349
|
2024-09-11 01:44 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312312
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verifi…
|
NVD-CWE-Other
|
CVE-2024-38886
|
2024-09-11 01:40 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312313
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of s…
|
CWE-89
SQL Injection
|
CVE-2024-38889
|
2024-09-11 01:38 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312314
|
- |
|
-
|
-
|
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
|
-
|
CVE-2023-37226
|
2024-09-11 01:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312315
|
- |
|
-
|
-
|
An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.
|
-
|
CVE-2024-42759
|
2024-09-11 01:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312316
|
- |
|
-
|
-
|
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook r…
|
-
|
CVE-2024-45393
|
2024-09-11 00:50 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312317
|
- |
|
-
|
-
|
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes a command in bconsole using an abbreviation (i.e. …
|
CWE-285
Improper Authorization
|
CVE-2024-45044
|
2024-09-11 00:50 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312318
|
- |
|
-
|
-
|
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 versio…
|
-
|
CVE-2024-8654
|
2024-09-11 00:50 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312319
|
- |
|
-
|
-
|
phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.
|
-
|
CVE-2024-44867
|
2024-09-11 00:50 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312320
|
4.3 |
MEDIUM
Network
|
oretnom23
|
food_ordering_management_system
|
A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerability affects unknown code of the file /foms/routers/place-order.php of the com…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2024-8558
|
2024-09-11 00:50 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|