|
251311
|
- |
|
-
|
-
|
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
|
-
|
CVE-2024-48655
|
2024-10-30 05:35 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251312
|
- |
|
-
|
-
|
A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jixiang Tenda) v.DI_7003G-19.12.24A1V16.03.29.50;V16.03.29.50;V16.03.29.50. An att…
|
-
|
CVE-2024-48459
|
2024-10-30 05:35 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251313
|
- |
|
-
|
-
|
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an inv…
|
-
|
CVE-2024-48426
|
2024-10-30 05:35 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251314
|
- |
|
-
|
-
|
Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys
|
-
|
CVE-2023-32189
|
2024-10-30 05:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251315
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via…
|
NVD-CWE-noinfo
|
CVE-2024-7978
|
2024-10-30 05:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251316
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discreti…
|
NVD-CWE-noinfo
|
CVE-2024-7004
|
2024-10-30 05:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251317
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, an…
|
NVD-CWE-noinfo
|
CVE-2024-7518
|
2024-10-30 05:35 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251318
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security sev…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-7255
|
2024-10-30 05:35 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251319
|
9.8 |
CRITICAL
Network
|
janobe
|
online_hotel_reservation_system
|
A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is the function upload of the file /guest/update.php. T…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-10413
|
2024-10-30 05:33 |
2024-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251320
|
7.2 |
HIGH
Network
|
janobe
|
online_hotel_reservation_system
|
A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0. It has been classified as critical. Affected is the function doCancelRoom/doCancel/doConfirm/doCancel/doCheckin/doChec…
|
CWE-89
SQL Injection
|
CVE-2024-10411
|
2024-10-30 05:28 |
2024-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|