|
312051
|
7.5 |
HIGH
Network
|
transsion
|
carlcare
|
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
|
NVD-CWE-noinfo
|
CVE-2024-7697
|
2024-09-7 03:04 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312052
|
8.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it.
Malicious software running in a guest VM that exposes virtio_scsi can exploi…
|
CWE-909
Missing Initialization of Resource
|
CVE-2024-8178
|
2024-09-7 02:35 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312053
|
8.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing.
Malicious software running in a guest VM that exposes virtio_scsi c…
|
CWE-416
Use After Free
|
CVE-2024-45063
|
2024-09-7 02:35 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312054
|
- |
|
-
|
-
|
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
|
-
|
CVE-2024-42919
|
2024-09-7 02:35 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312055
|
- |
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
|
-
|
CVE-2024-42557
|
2024-09-7 02:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312056
|
7.5 |
HIGH
Network
|
rust-bitcoin
|
miniscript
|
The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44073
|
2024-09-7 02:35 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312057
|
- |
|
-
|
-
|
The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include…
|
-
|
CVE-2024-6459
|
2024-09-7 02:35 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312058
|
9.8 |
CRITICAL
Network
|
totolink
|
lr350_firmware
|
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-…
|
NVD-CWE-noinfo
|
CVE-2024-42967
|
2024-09-7 02:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312059
|
9.8 |
CRITICAL
Network
|
tenda
|
fh1201_firmware
|
An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.
|
NVD-CWE-noinfo
|
CVE-2024-42947
|
2024-09-7 02:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312060
|
7.8 |
HIGH
Local
|
cysoft168
|
super_easy_enterprise_management_system
|
SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.
|
CWE-89
SQL Injection
|
CVE-2024-42679
|
2024-09-7 02:35 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|