|
248911
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause multiple secondaries crashing leading to no prima…
|
NVD-CWE-Other
|
CVE-2024-8305
|
2024-11-8 00:38 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248912
|
6.1 |
MEDIUM
Network
|
klokantech
|
maptiler_tileserver_gl
|
A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some unknown processing of the component URL Handler. The manipulation of the argume…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10503
|
2024-11-8 00:30 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248913
|
7.5 |
HIGH
Network
|
nginxui
|
nginx_ui
|
Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of …
|
CWE-22
Path Traversal
|
CVE-2024-49366
|
2024-11-8 00:15 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248914
|
7.5 |
HIGH
Network
|
nginxui
|
nginx_ui
|
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/co…
|
CWE-862
Missing Authorization
|
CVE-2024-49367
|
2024-11-7 23:57 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248915
|
- |
|
-
|
-
|
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.
|
-
|
CVE-2024-50637
|
2024-11-7 23:15 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248916
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ALSA: seq: Fix function prototype mismatch in snd_seq_expand_var_event
With clang's kernel control flow integrity (kCFI, CONFIG_C…
|
NVD-CWE-noinfo
|
CVE-2022-48994
|
2024-11-7 22:52 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248917
|
7.8 |
HIGH
Local
|
2n
|
access_commander
|
In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary
code execution with root permissions.
|
NVD-CWE-noinfo
|
CVE-2024-47255
|
2024-11-7 21:15 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248918
|
7.2 |
HIGH
Network
|
2n
|
access_commander
|
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient
Verification of Data Authenticity vulnerability could allow an attacker
to escalate their privileges and gain root access to the s…
|
NVD-CWE-noinfo
|
CVE-2024-47254
|
2024-11-7 21:15 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248919
|
7.2 |
HIGH
Network
|
2n
|
access_commander
|
In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem and potentially achieve arbit…
|
CWE-22
Path Traversal
|
CVE-2024-47253
|
2024-11-7 21:15 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248920
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_adaudit_plus
|
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
|
CWE-89
SQL Injection
|
CVE-2024-36485
|
2024-11-7 20:15 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|