|
312011
|
9.8 |
CRITICAL
Network
|
oretnom23
|
clinic\'s_patient_management_system
|
A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is the function patient_name of the file patients.php…
|
CWE-89
SQL Injection
|
CVE-2024-7454
|
2024-09-7 21:56 |
2024-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312012
|
9.8 |
CRITICAL
Network
|
onesoftnet
|
sudobot
|
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of …
|
CWE-862
Missing Authorization
|
CVE-2024-45307
|
2024-09-7 10:34 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312013
|
6.1 |
MEDIUM
Network
|
xiebruce
|
picuploader
|
A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44796
|
2024-09-7 08:35 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312014
|
8.8 |
HIGH
Network
|
roxy-wi
|
roxy-wi
|
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code…
|
CWE-78
OS Command
|
CVE-2024-43804
|
2024-09-7 07:57 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312015
|
8.1 |
HIGH
Network
|
getkirby
|
kirby
|
Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for creating and de…
|
CWE-863
Incorrect Authorization
|
CVE-2024-41964
|
2024-09-7 07:56 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312016
|
5.4 |
MEDIUM
Network
|
seacms
|
seacms
|
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad descript…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44919
|
2024-09-7 07:54 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312017
|
9.8 |
CRITICAL
Network
|
deltaww
|
dtn_soft
|
Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-8255
|
2024-09-7 07:53 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312018
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and le…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-5991
|
2024-09-7 07:51 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312019
|
9.8 |
CRITICAL
Network
|
hp
|
security_manager
|
HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.
|
NVD-CWE-noinfo
|
CVE-2024-7720
|
2024-09-7 07:33 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312020
|
6.1 |
MEDIUM
Network
|
gazelle_project
|
gazelle
|
A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inj…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44797
|
2024-09-7 07:27 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|