|
312141
|
6.1 |
MEDIUM
Network
|
angeljudesuarez
|
event_management_system
|
Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44728
|
2024-09-6 22:23 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312142
|
6.1 |
MEDIUM
Network
|
1e
|
platform
|
The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users.
…
|
CWE-601
Open Redirect
|
CVE-2024-7211
|
2024-09-6 22:23 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312143
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mm: page_ref: remove folio_try_get_rcu()
The below bug was reported on a non-SMP kernel:
[ 275.267158][ T4335] ------------[ cu…
|
CWE-617
Reachable Assertion
|
CVE-2024-42251
|
2024-09-6 22:21 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312144
|
9.8 |
CRITICAL
Network
|
angeljudesuarez
|
event_management_system
|
Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.
|
CWE-89
SQL Injection
|
CVE-2024-44727
|
2024-09-6 22:15 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312145
|
9.1 |
CRITICAL
Network
|
mindsdb
|
mindsdb
|
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-24759
|
2024-09-6 22:06 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312146
|
8.1 |
HIGH
Network
|
ibm
|
aspera_faspex
|
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
|
NVD-CWE-noinfo
|
CVE-2024-45098
|
2024-09-6 22:01 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312147
|
7.1 |
HIGH
Network
|
ibm
|
aspera_faspex
|
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
|
CWE-436
Interpretation Conflict
|
CVE-2024-45097
|
2024-09-6 21:51 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312148
|
6.5 |
MEDIUM
Network
|
ibm
|
aspera_faspex
|
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.
|
NVD-CWE-Other
|
CVE-2024-45096
|
2024-09-6 21:34 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312149
|
- |
|
-
|
-
|
An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest…
|
-
|
CVE-2024-45158
|
2024-09-6 21:08 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312150
|
- |
|
-
|
-
|
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts…
|
-
|
CVE-2024-42491
|
2024-09-6 21:08 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|