|
248961
|
- |
|
-
|
-
|
Missing Authorization vulnerability in ??????? ????? Persian WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Persian WooCommerce: from n/a through 7.1.6.
|
CWE-862
Missing Authorization
|
CVE-2024-43219
|
2024-11-6 07:15 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248962
|
8.8 |
HIGH
Network
|
wpchill
|
strong_testimonials
|
Missing Authorization vulnerability in WPChill Strong Testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through 3.1…
|
CWE-862
Missing Authorization
|
CVE-2024-47362
|
2024-11-6 06:44 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248963
|
9.8 |
CRITICAL
Network
|
lb-link
|
bl-wr1300h_firmware
|
LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-51431
|
2024-11-6 06:37 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248964
|
7.5 |
HIGH
Network
|
tp-link
|
mr200_firmware
|
TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which …
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-22733
|
2024-11-6 06:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248965
|
- |
|
-
|
-
|
A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack d…
|
-
|
CVE-2024-47224
|
2024-11-6 06:35 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248966
|
5.3 |
MEDIUM
Network
|
vmware
|
spring_framework
|
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields no…
|
NVD-CWE-noinfo
|
CVE-2024-38820
|
2024-11-6 06:35 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248967
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.
|
-
|
CVE-2024-24510
|
2024-11-6 06:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248968
|
8.8 |
HIGH
Network
|
esafenet
|
cdg
|
A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/policy/HookWhiteListService…
|
CWE-89
SQL Injection
|
CVE-2024-10500
|
2024-11-6 06:02 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248969
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor3900_firmware
|
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.
|
CWE-78
OS Command
|
CVE-2024-51252
|
2024-11-6 05:54 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248970
|
- |
|
-
|
-
|
Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possession of the encrypted file to decrypt the bof.cfg file and obtain the BOF configur…
|
-
|
CVE-2023-6728
|
2024-11-6 05:35 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|