|
313601
|
- |
|
-
|
-
|
parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload process. The XSS vulne…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-5125
|
2024-11-16 01:35 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313602
|
7.8 |
HIGH
Local
|
samsung
|
android
|
Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behavi…
|
NVD-CWE-noinfo
|
CVE-2024-34662
|
2024-11-16 01:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313603
|
6.1 |
MEDIUM
Network
|
alist_project
|
alist
|
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47067
|
2024-11-16 01:28 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313604
|
8.8 |
HIGH
Network
|
microsoft
|
sql_server_2016 sql_server_2017 sql_server_2019
|
SQL Server Native Client Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-49012
|
2024-11-16 01:16 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313605
|
8.8 |
HIGH
Network
|
microsoft
|
sql_server_2016 sql_server_2017 sql_server_2019
|
SQL Server Native Client Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-49011
|
2024-11-16 01:16 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313606
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2414. Reason: This candidate is a reservation duplicate of CVE-2023-2414. Notes: All CVE users should reference CV…
|
-
|
CVE-2024-7865
|
2024-11-16 01:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313607
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2414. Reason: This candidate is a reservation duplicate of CVE-2023-2414. Notes: All CVE users should reference C…
|
-
|
CVE-2024-6413
|
2024-11-16 01:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313608
|
8.8 |
HIGH
Network
|
microsoft
|
sql_server_2016 sql_server_2017 sql_server_2019
|
SQL Server Native Client Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-49013
|
2024-11-16 01:14 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313609
|
8.8 |
HIGH
Network
|
microsoft
|
sql_server_2016 sql_server_2017 sql_server_2019
|
SQL Server Native Client Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-49017
|
2024-11-16 01:07 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313610
|
8.8 |
HIGH
Network
|
microsoft
|
sql_server_2016 sql_server_2017 sql_server_2019
|
SQL Server Native Client Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-49016
|
2024-11-16 01:07 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|