|
249421
|
- |
|
-
|
-
|
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 an…
|
-
|
CVE-2024-44234
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249422
|
- |
|
-
|
-
|
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 an…
|
-
|
CVE-2024-44233
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249423
|
- |
|
-
|
-
|
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 an…
|
-
|
CVE-2024-44232
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249424
|
6.5 |
MEDIUM
Network
|
lunary
|
lunary
|
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' p…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-7473
|
2024-11-4 02:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249425
|
7.1 |
HIGH
Network
|
lollms
|
lollms_web_ui
|
A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a mult…
|
CWE-352
Origin Validation Error
|
CVE-2024-6959
|
2024-11-4 02:15 |
2024-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249426
|
2.7 |
LOW
Network
|
openwebui
|
open_webui
|
An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-7038
|
2024-11-4 02:15 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249427
|
4.3 |
MEDIUM
Network
|
lunary
|
lunary
|
A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-6582
|
2024-11-4 02:15 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249428
|
7.1 |
HIGH
Local
|
apple
|
macos
|
A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to bypass …
|
NVD-CWE-noinfo
|
CVE-2024-44159
|
2024-11-2 06:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249429
|
- |
|
-
|
-
|
Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLog…
|
-
|
CVE-2024-37879
|
2024-11-2 06:35 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249430
|
- |
|
-
|
-
|
The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.
|
-
|
CVE-2024-7084
|
2024-11-2 06:35 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|