|
248821
|
- |
|
-
|
-
|
In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions o…
|
-
|
CVE-2024-48052
|
2024-11-7 05:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248822
|
- |
|
-
|
-
|
An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web app…
|
-
|
CVE-2024-28808
|
2024-11-7 05:35 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248823
|
- |
|
-
|
-
|
A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitiv…
|
-
|
CVE-2024-39339
|
2024-11-7 05:35 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248824
|
- |
|
-
|
-
|
An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters embed credentials w…
|
-
|
CVE-2024-42018
|
2024-11-7 05:35 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248825
|
6.1 |
MEDIUM
Network
|
ahmetimamoglu
|
ahmeti_wp_timeline
|
Cross-Site Request Forgery (CSRF) vulnerability in Ahmet Imamoglu Ahmeti Wp Timeline allows Stored XSS.This issue affects Ahmeti Wp Timeline: from n/a through 5.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-49237
|
2024-11-7 05:33 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248826
|
- |
|
-
|
-
|
Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.
|
-
|
CVE-2024-48463
|
2024-11-7 04:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248827
|
- |
|
-
|
-
|
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, Mode…
|
-
|
CVE-2024-45185
|
2024-11-7 04:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248828
|
- |
|
-
|
-
|
This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.…
|
-
|
CVE-2024-21690
|
2024-11-7 04:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248829
|
4.8 |
MEDIUM
Network
|
migaweb
|
accordion_title_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Accordion title for Elementor allows Stored XSS.This issue affects Accordi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51685
|
2024-11-7 04:34 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248830
|
7.5 |
HIGH
Network
|
aetherproject
|
onos-a1t sdran-in-a-box
|
An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component of the sdran-in-a-box, specificall…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-48809
|
2024-11-7 04:33 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|