|
249461
|
- |
|
-
|
-
|
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.
|
-
|
CVE-2024-51296
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249462
|
- |
|
-
|
-
|
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.
|
-
|
CVE-2024-51257
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249463
|
- |
|
-
|
-
|
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.
|
-
|
CVE-2024-51304
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249464
|
- |
|
-
|
-
|
In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that …
|
-
|
CVE-2024-3935
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249465
|
- |
|
-
|
-
|
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access whe…
|
-
|
CVE-2024-10525
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249466
|
- |
|
-
|
-
|
The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.7 due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9388
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249467
|
9.1 |
CRITICAL
Network
|
-
|
-
|
The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 via the 'script' parameter of the hookBeforeStartOptimization() function. This i…
|
CWE-95
Eval Injection
|
CVE-2024-8512
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249468
|
- |
|
-
|
-
|
Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping allows Retrieve Embedded Sensitive Data.This issue affects Posti Shipping: from n/a through 3.10.2.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-50512
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249469
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in David DONISA WP donimedia carousel allows Upload a Web Shell to a Web Server.This issue affects WP donimedia carousel: from n/a throug…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-50511
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249470
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in Web and Print Design AR For Woocommerce allows Upload a Web Shell to a Web Server.This issue affects AR For Woocommerce: from n/a thro…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-50510
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|