|
312201
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-35294
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312202
|
9.1 |
CRITICAL
Network
|
-
|
-
|
An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-35293
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312203
|
- |
|
-
|
-
|
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation
|
-
|
CVE-2024-9333
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312204
|
- |
|
-
|
-
|
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
|
-
|
CVE-2024-9174
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312205
|
- |
|
-
|
-
|
The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to…
|
-
|
CVE-2024-7315
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312206
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7855
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312207
|
- |
|
-
|
-
|
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.
|
-
|
CVE-2024-45186
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312208
|
- |
|
-
|
-
|
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
|
-
|
CVE-2024-33662
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312209
|
- |
|
-
|
-
|
Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the …
|
-
|
CVE-2024-21530
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312210
|
- |
|
-
|
-
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary Java…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47526
|
2024-10-4 22:50 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|