|
312591
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-8389
|
2024-09-5 00:50 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312592
|
9.8 |
CRITICAL
Network
|
seacms
|
seacms
|
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
|
CWE-89
SQL Injection
|
CVE-2024-44921
|
2024-09-5 00:00 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312593
|
6.1 |
MEDIUM
Network
|
seacms
|
seacms
|
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the si…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44920
|
2024-09-4 23:59 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312594
|
9.8 |
CRITICAL
Network
|
rems
|
contact_manager_with_export_to_vcf
|
A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing of the file /endpoint/delete-account.php …
|
CWE-89
SQL Injection
|
CVE-2024-8380
|
2024-09-4 23:58 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312595
|
5.4 |
MEDIUM
Network
|
3ds
|
3dexperience_enovia
|
A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8004
|
2024-09-4 23:56 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312596
|
5.4 |
MEDIUM
Network
|
3ds
|
3dexperience
|
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7938
|
2024-09-4 23:53 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312597
|
6.1 |
MEDIUM
Network
|
checkmk
|
checkmk
|
Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.
|
CWE-79
Cross-site Scripting
|
CVE-2024-38858
|
2024-09-4 23:39 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312598
|
6.5 |
MEDIUM
Network
|
hashicorp
|
vault
|
Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors,…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-8365
|
2024-09-4 23:37 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312599
|
- |
|
-
|
-
|
Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-8362
|
2024-09-4 23:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312600
|
- |
|
-
|
-
|
Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-7970
|
2024-09-4 23:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|