|
249691
|
9.1 |
CRITICAL
Network
|
langchain
|
langchain
|
A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite ex…
|
CWE-22
Path Traversal
|
CVE-2024-7774
|
2024-11-1 00:39 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249692
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
|
CWE-89
SQL Injection
|
CVE-2024-48226
|
2024-11-1 00:38 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249693
|
6.5 |
MEDIUM
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
|
NVD-CWE-noinfo
|
CVE-2024-48225
|
2024-11-1 00:35 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249694
|
- |
|
-
|
-
|
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configurat…
|
-
|
CVE-2024-20280
|
2024-11-1 00:35 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249695
|
- |
|
-
|
-
|
Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting …
|
-
|
CVE-2023-31310
|
2024-11-1 00:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249696
|
4.9 |
MEDIUM
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.
|
CWE-22
Path Traversal
|
CVE-2024-48224
|
2024-11-1 00:32 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249697
|
6.1 |
MEDIUM
Network
|
manzurulhaque
|
banner_slider
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Manzurul Haque Banner Slider allows Reflected XSS.This issue affects Banner Slider: from n…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49635
|
2024-11-1 00:27 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249698
|
5.3 |
MEDIUM
Network
|
hcltech
|
sametime
|
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2023-50355
|
2024-11-1 00:18 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249699
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird firefox
|
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR <…
|
CWE-416
Use After Free
|
CVE-2024-10459
|
2024-11-1 00:16 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249700
|
4.3 |
MEDIUM
Network
|
rockoa
|
xinhu
|
RockOA v2.6.5 is vulnerable to Directory Traversal in webmain/system/beifen/beifenAction.php.
|
CWE-22
Path Traversal
|
CVE-2024-48213
|
2024-11-1 00:09 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|