|
314601
|
- |
|
-
|
-
|
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
|
-
|
CVE-2024-32840
|
2024-09-12 11:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314602
|
- |
|
-
|
-
|
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
|
-
|
CVE-2024-29847
|
2024-09-12 11:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314603
|
- |
|
-
|
-
|
A vulnerability was found in ?????????? Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile of the file application/admin/con…
|
CWE-22
Path Traversal
|
CVE-2024-8707
|
2024-09-12 10:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314604
|
7.3 |
HIGH
Local
|
microsoft
|
office publisher
|
Microsoft Publisher Security Feature Bypass Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38226
|
2024-09-12 10:00 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314605
|
- |
|
-
|
-
|
A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.Templat…
|
CWE-22
Path Traversal
|
CVE-2024-8706
|
2024-09-12 09:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314606
|
- |
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
|
-
|
CVE-2024-28981
|
2024-09-12 09:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314607
|
6.1 |
MEDIUM
Network
|
friendica
|
friendica
|
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature.
|
CWE-79
Cross-site Scripting
|
CVE-2024-27729
|
2024-09-12 05:29 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314608
|
6.5 |
MEDIUM
Network
|
elastic
|
apm_server
|
APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains the…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-37286
|
2024-09-12 05:20 |
2024-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314609
|
9.8 |
CRITICAL
Network
|
angeljudesuarez
|
airline_reservation_system
|
A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of the file admin/admin_class.php. The ma…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7500
|
2024-09-12 05:07 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314610
|
8.8 |
HIGH
Network
|
angeljudesuarez
|
tailoring_management_system
|
A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /setlogo.php. The man…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7506
|
2024-09-12 05:02 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|