|
251451
|
- |
|
-
|
-
|
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this…
|
-
|
CVE-2024-30124
|
2024-10-30 00:35 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251452
|
- |
|
-
|
-
|
An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an…
|
-
|
CVE-2024-42017
|
2024-10-30 00:35 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251453
|
- |
|
sgi
|
irix
|
root privileges via buffer overflow in ordist command on SGI IRIX systems.
|
NVD-CWE-Other
|
CVE-1999-0029
|
2024-10-30 00:35 |
1997-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251454
|
5.4 |
MEDIUM
Network
|
hikashop
|
hikashop
|
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious p…
|
CWE-79
Cross-site Scripting
|
CVE-2024-40746
|
2024-10-30 00:34 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251455
|
5.4 |
MEDIUM
Network
|
jesweb
|
anchor_episodes_index
|
The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's anchor_episodes shortcode in all versions up to, and including, 2…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10189
|
2024-10-30 00:27 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251456
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause a coprocessor crash.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-40810
|
2024-10-30 00:21 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251457
|
4.3 |
MEDIUM
Network
|
colorlib
|
simple_custom_post_order
|
Missing Authorization vulnerability in Colorlib Simple Custom Post Order allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Custom Post Order: from n/a …
|
CWE-862
Missing Authorization
|
CVE-2024-49321
|
2024-10-30 00:20 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251458
|
5.4 |
MEDIUM
Network
|
rextheme
|
wp_vr
|
Missing Authorization vulnerability in Rextheme WP VR allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 8.5.4.
|
CWE-862
Missing Authorization
|
CVE-2024-49293
|
2024-10-30 00:07 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251459
|
6.1 |
MEDIUM
Network
|
edit_woocommerce_templates_project
|
edit_woocommerce_templates
|
The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10049
|
2024-10-29 23:49 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251460
|
8.2 |
HIGH
Adjacent
|
eufy
|
homebase_2_firmware
|
The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serves as a proxy to the end user's primary network. The WPA2-PSK generation of this…
|
CWE-331
Insufficient Entropy
|
CVE-2023-37822
|
2024-10-29 23:47 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|