|
249331
|
- |
|
-
|
-
|
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.
|
-
|
CVE-2024-51064
|
2024-11-2 01:35 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249332
|
- |
|
-
|
-
|
An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe)
|
-
|
CVE-2024-48200
|
2024-11-2 01:35 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249333
|
- |
|
-
|
-
|
Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded character…
|
-
|
CVE-2024-42515
|
2024-11-2 01:35 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249334
|
- |
|
-
|
-
|
Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.
|
-
|
CVE-2024-39332
|
2024-11-2 01:35 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249335
|
- |
|
-
|
-
|
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.
|
-
|
CVE-2023-52044
|
2024-11-2 01:35 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249336
|
- |
|
-
|
-
|
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges t…
|
CWE-59
Link Following
|
CVE-2024-45315
|
2024-11-2 01:35 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249337
|
- |
|
-
|
-
|
Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/…
|
-
|
CVE-2024-8037
|
2024-11-2 01:35 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249338
|
9.8 |
CRITICAL
Network
|
tenda
|
ac1206_firmware
|
A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ate_Tenda_mfg_check_usb/ate_Tenda_mfg_check_usb3 of the file /goform/ate. The m…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-10434
|
2024-11-2 01:32 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249339
|
7.8 |
HIGH
Local
|
autodesk
|
autocad autocad_advance_steel autocad_architecture autocad_civil_3d autocad_electrical autocad_mechanical autocad_mep autocad_plant_3d dwg_trueview autocad_lt
|
A maliciously crafted DWG file when parsed in acdb25.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, wri…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-9997
|
2024-11-2 01:27 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249340
|
7.8 |
HIGH
Local
|
autodesk
|
autocad autocad_advance_steel autocad_architecture autocad_civil_3d autocad_electrical autocad_mechanical autocad_mep autocad_plant_3d dwg_trueview autocad_lt
|
A maliciously crafted DWG file when parsed in acdb25.dll through Autodesk AutoCAD can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-9996
|
2024-11-2 01:27 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|