|
249551
|
7.5 |
HIGH
Network
|
mintplexlabs
|
anythingllm
|
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in s…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-7783
|
2024-11-1 00:49 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249552
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
|
CWE-89
SQL Injection
|
CVE-2024-48229
|
2024-11-1 00:49 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249553
|
4.9 |
MEDIUM
Network
|
funadmin
|
funadmin
|
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).
|
NVD-CWE-noinfo
|
CVE-2024-48227
|
2024-11-1 00:48 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249554
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
|
CWE-89
SQL Injection
|
CVE-2024-48223
|
2024-11-1 00:44 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249555
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
|
CWE-89
SQL Injection
|
CVE-2024-48222
|
2024-11-1 00:44 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249556
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
|
CWE-89
SQL Injection
|
CVE-2024-48218
|
2024-11-1 00:44 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249557
|
9.1 |
CRITICAL
Network
|
langchain
|
langchain
|
A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite ex…
|
CWE-22
Path Traversal
|
CVE-2024-7774
|
2024-11-1 00:39 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249558
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
|
CWE-89
SQL Injection
|
CVE-2024-48226
|
2024-11-1 00:38 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249559
|
6.5 |
MEDIUM
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
|
NVD-CWE-noinfo
|
CVE-2024-48225
|
2024-11-1 00:35 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249560
|
- |
|
-
|
-
|
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configurat…
|
-
|
CVE-2024-20280
|
2024-11-1 00:35 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|