|
249501
|
8.8 |
HIGH
Network
|
tenda
|
rx9_pro_firmware
|
A vulnerability classified as critical has been found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected is the function sub_42EEE0 of the file /goform/SetStaticRouteCfg. The manipulation of …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-10281
|
2024-11-1 22:52 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249502
|
8.8 |
HIGH
Network
|
tenda
|
rx9_pro_firmware
|
A vulnerability classified as critical was found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected by this vulnerability is the function sub_42EA38 of the file /goform/SetVirtualServerCfg. T…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-10282
|
2024-11-1 22:47 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249503
|
- |
|
-
|
-
|
Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by manipulating default path during file down…
|
-
|
CVE-2024-48735
|
2024-11-1 22:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249504
|
- |
|
-
|
-
|
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
|
-
|
CVE-2024-48063
|
2024-11-1 22:15 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249505
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10367
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249506
|
6.1 |
MEDIUM
Network
|
-
|
-
|
IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform Refl…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10652
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249507
|
4.9 |
MEDIUM
Network
|
-
|
-
|
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this v…
|
CWE-36
Absolute Path Traversal
|
CVE-2024-10651
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249508
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atomchat shortcode in all versions up to, and including, 1.1.5 due to insuff…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10232
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249509
|
- |
|
-
|
-
|
A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file /com/esafenet/servlet/ajax/Public…
|
CWE-89
SQL Injection
|
CVE-2024-10595
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249510
|
- |
|
-
|
-
|
Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.
|
-
|
CVE-2024-48360
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|