|
311921
|
5.5 |
MEDIUM
Local
|
samsung
|
exynos_980_firmware exynos_850_firmware exynos_1080_firmware exynos_1280_firmware exynos_1380_firmware exynos_1330_firmware exynos_1480_firmware exynos_w920_firmware exynos_w9…
|
An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, E…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-27368
|
2024-09-12 00:25 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311922
|
7.8 |
HIGH
Local
|
samsung
|
exynos_1080_firmware exynos_1280_firmware exynos_1330_firmware exynos_1380_firmware exynos_1480_firmware exynos_850_firmware exynos_980_firmware exynos_w920_firmware exynos_w9…
|
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is no input validation check on …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-27387
|
2024-09-12 00:23 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311923
|
- |
|
-
|
-
|
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" in…
|
-
|
CVE-2024-37728
|
2024-09-12 00:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311924
|
4.4 |
MEDIUM
Local
|
avaya
|
aura_system_manager
|
An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the sys…
|
NVD-CWE-noinfo
|
CVE-2024-7480
|
2024-09-12 00:03 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311925
|
6.7 |
MEDIUM
Local
|
avaya
|
aura_system_manager
|
A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager databas…
|
CWE-89
SQL Injection
|
CVE-2024-7477
|
2024-09-12 00:03 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311926
|
8.8 |
HIGH
Network
|
e-bmsoft
|
bmplanning
|
SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly other parame…
|
CWE-89
SQL Injection
|
CVE-2024-28298
|
2024-09-11 23:54 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311927
|
9.6 |
CRITICAL
Network
|
monkeytype
|
monkeytype
|
Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-failure-comment.yml GitHub Workflow, enabling attac…
|
CWE-94
Code Injection
|
CVE-2024-41127
|
2024-09-11 23:52 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311928
|
8.8 |
HIGH
Network
|
dlink
|
di-8100_firmware
|
A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07. This issue affects the function msp_info_htm of the file msp_info.htm. The manipulation of the argument cmd …
|
CWE-77
Command Injection
|
CVE-2024-7436
|
2024-09-11 23:41 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311929
|
4.3 |
MEDIUM
Network
|
simplemachines
|
simple_machines_forum
|
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=sho…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-7438
|
2024-09-11 23:39 |
2024-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311930
|
4.3 |
MEDIUM
Network
|
simplemachines
|
simple_machines_forum
|
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the co…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-7437
|
2024-09-11 23:39 |
2024-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|