|
312251
|
6.5 |
MEDIUM
Network
|
digiwin
|
easyflow_.net
|
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vuln…
|
CWE-22
Path Traversal
|
CVE-2024-7323
|
2024-09-11 23:22 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312252
|
9.8 |
CRITICAL
Network
|
forip
|
administracao_pabx
|
A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of the file /authMonitCallcenter of the compo…
|
CWE-89
SQL Injection
|
CVE-2024-7461
|
2024-09-11 23:16 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312253
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-7805
|
2024-09-11 23:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312254
|
6.1 |
MEDIUM
Network
|
lang-learn-guy
|
learning_with_texts
|
Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-41572
|
2024-09-11 23:15 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312255
|
5.9 |
MEDIUM
Network
|
ibm
|
java_sdk
|
The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the …
|
NVD-CWE-noinfo
|
CVE-2024-27267
|
2024-09-11 22:48 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312256
|
6.5 |
MEDIUM
Network
|
qnap
|
qts quts_hero
|
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expos…
|
CWE-22
Path Traversal
|
CVE-2024-21904
|
2024-09-11 22:40 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312257
|
5.9 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued b…
|
NVD-CWE-Other
|
CVE-2023-50315
|
2024-09-11 22:38 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312258
|
4.7 |
MEDIUM
Network
|
qnap
|
qts quts_hero
|
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands …
|
CWE-78 CWE-77
OS Command Command Injection
|
CVE-2024-21903
|
2024-09-11 22:36 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312259
|
8.8 |
HIGH
Network
|
qnap
|
qts quts_hero
|
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a net…
|
CWE-78
OS Command
|
CVE-2024-21898
|
2024-09-11 22:35 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312260
|
5.4 |
MEDIUM
Network
|
qnap
|
qts quts_hero
|
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code…
|
CWE-79
Cross-site Scripting
|
CVE-2024-21897
|
2024-09-11 22:34 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|