|
250251
|
4.8 |
MEDIUM
Network
|
nsqua
|
simply_schedule_appointments
|
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow h…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7876
|
2024-11-7 00:42 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250252
|
9.8 |
CRITICAL
Network
|
helloprint
|
helloprint
|
Unrestricted Upload of File with Dangerous Type vulnerability in Helloprint Plug your WooCommerce into the largest catalog of customized print products from Helloprint allows Upload a Web Shell to a …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-50525
|
2024-11-7 00:42 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250253
|
- |
|
-
|
-
|
An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room…
|
-
|
CVE-2024-42773
|
2024-11-7 00:35 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250254
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_exchange_reporter_plus
|
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.
|
CWE-89
SQL Injection
|
CVE-2024-9459
|
2024-11-7 00:29 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250255
|
7.5 |
HIGH
Network
|
zimaspace
|
zimaos
|
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/use…
|
CWE-862
Missing Authorization
|
CVE-2024-49357
|
2024-11-7 00:28 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250256
|
7.5 |
HIGH
Network
|
zimaspace
|
zimaos
|
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in Zi…
|
CWE-22
Path Traversal
|
CVE-2024-49359
|
2024-11-7 00:27 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250257
|
5.3 |
MEDIUM
Network
|
zimaspace
|
zimaos
|
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-49358
|
2024-11-7 00:27 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250258
|
5.5 |
MEDIUM
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-47402
|
2024-11-7 00:26 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250259
|
7.8 |
HIGH
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47137
|
2024-11-7 00:26 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250260
|
7.8 |
HIGH
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.
|
CWE-415
Double Free
|
CVE-2024-47404
|
2024-11-7 00:25 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|