|
249361
|
4.3 |
MEDIUM
Network
|
dena
|
h2o
|
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers handler allows users to modify the response headers being sent by h2o. The con…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2024-25622
|
2024-11-13 05:04 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249362
|
9.8 |
CRITICAL
Network
|
dena
|
picotls
|
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically, bindings within pico…
|
CWE-415
Double Free
|
CVE-2024-45402
|
2024-11-13 05:02 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249363
|
7.5 |
HIGH
Network
|
dena
|
h2o
|
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3 requests are cancelled by the client, h2o might crash due to an assertion fail…
|
CWE-617
Reachable Assertion
|
CVE-2024-45403
|
2024-11-13 04:59 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249364
|
5.8 |
MEDIUM
Network
|
plane
|
plane
|
Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-47830
|
2024-11-13 04:55 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249365
|
9.8 |
CRITICAL
Network
|
dataease
|
dataease
|
DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-47074
|
2024-11-13 04:52 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249366
|
7.8 |
HIGH
Local
|
workbooth_project
|
workbooth
|
Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.
|
NVD-CWE-noinfo
|
CVE-2024-9576
|
2024-11-13 04:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249367
|
7.5 |
HIGH
Network
|
finrota
|
finrota
|
Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
|
CWE-202 CWE-311 CWE-312
Exposure of Sensitive Information Through Data Queries Missing Encryption of Sensitive Data Cleartext Storage of Sensitive Information
|
CVE-2024-6400
|
2024-11-13 04:32 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249368
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2024-6443
|
2024-11-13 04:29 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249369
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.
|
-
|
CVE-2024-51213
|
2024-11-13 03:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249370
|
- |
|
-
|
-
|
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= fiel…
|
-
|
CVE-2024-51026
|
2024-11-13 03:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|