|
312001
|
- |
|
-
|
-
|
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
|
-
|
CVE-2024-39718
|
2024-09-9 22:03 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312002
|
- |
|
-
|
-
|
Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.co…
|
-
|
CVE-2023-46809
|
2024-09-9 22:03 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312003
|
6.6 |
MEDIUM
Network
|
-
|
-
|
The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions up to, and including, 0.9.7. Th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7620
|
2024-09-9 22:03 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312004
|
- |
|
-
|
-
|
A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Comman…
|
CWE-94
Code Injection
|
CVE-2024-8523
|
2024-09-9 22:03 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312005
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument man…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8521
|
2024-09-9 22:03 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312006
|
- |
|
-
|
-
|
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affe…
|
-
|
CVE-2024-7652
|
2024-09-9 22:03 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312007
|
7.8 |
HIGH
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
|
CWE-416
Use After Free
|
CVE-2024-41160
|
2024-09-9 21:21 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312008
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-42334
|
2024-09-8 21:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312009
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to truncate preallocated blocks in f2fs_file_open()
chenyuwen reports a f2fs bug as below:
Unable to handle kernel NUL…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-43859
|
2024-09-8 17:15 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312010
|
9.8 |
CRITICAL
Network
|
ibm
|
security_directory_integrator security_verify_directory_integrator
|
IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a sign…
|
NVD-CWE-noinfo
|
CVE-2022-33162
|
2024-09-7 22:15 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|