|
251631
|
7.1 |
HIGH
Local
|
microsoft
|
azure_monitor_agent
|
Azure Monitor Agent Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38097
|
2024-10-17 04:28 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251632
|
6.1 |
MEDIUM
Network
|
microchip
|
timeprovider_4100_firmware
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43687
|
2024-10-17 04:28 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251633
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2022_23h2
|
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38029
|
2024-10-17 04:27 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251634
|
6.1 |
MEDIUM
Network
|
microchip
|
timeprovider_4100_firmware
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects Ti…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43686
|
2024-10-17 04:20 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251635
|
8.2 |
HIGH
Network
|
cacti
|
cacti
|
Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewse…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43365
|
2024-10-17 04:15 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251636
|
8.8 |
HIGH
Network
|
phpoffice
|
phpspreadsheet
|
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When embedding images h…
|
CWE-22 CWE-918
Path Traversal Server-Side Request Forgery (SSRF)
|
CVE-2024-45291
|
2024-10-17 04:09 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251637
|
5.3 |
MEDIUM
Network
|
php-fpm
|
php-fpm
|
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being proce…
|
NVD-CWE-noinfo
|
CVE-2024-8925
|
2024-10-17 03:53 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251638
|
- |
|
-
|
-
|
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.
|
-
|
CVE-2024-46532
|
2024-10-17 03:35 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251639
|
8.8 |
HIGH
Network
|
php-fpm
|
php-fpm
|
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for CVE-2024-4577 https://github.com/a…
|
CWE-78
OS Command
|
CVE-2024-8926
|
2024-10-17 03:35 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251640
|
3.3 |
LOW
Local
|
php-fpm
|
php-fpm
|
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possi…
|
NVD-CWE-Other
|
CVE-2024-9026
|
2024-10-17 03:30 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|