|
249771
|
7.8 |
HIGH
Local
|
apple
|
macos ipados iphone_os visionos
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sequoia 15, iOS 17.7 and iPadOS 17.7, macOS Sonoma 14.7, visionOS 2, iOS 18 and iPadOS 18. Processing …
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44126
|
2024-10-31 06:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249772
|
- |
|
-
|
-
|
PbootCMS 3.2.8 is vulnerable to URL Redirect.
|
-
|
CVE-2024-42930
|
2024-10-31 06:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249773
|
- |
|
-
|
-
|
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.
|
-
|
CVE-2024-39205
|
2024-10-31 06:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249774
|
- |
|
-
|
-
|
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to job…
|
-
|
CVE-2024-48936
|
2024-10-31 06:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249775
|
- |
|
-
|
-
|
ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.e…
|
-
|
CVE-2024-50624
|
2024-10-31 06:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249776
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security seve…
|
NVD-CWE-noinfo
|
CVE-2024-7974
|
2024-10-31 06:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249777
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr
|
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header pr…
|
NVD-CWE-noinfo
|
CVE-2024-7531
|
2024-10-31 06:35 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249778
|
8.8 |
HIGH
Network
|
zimbra
|
collaboration
|
An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Si…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-45518
|
2024-10-31 06:23 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249779
|
7.8 |
HIGH
Local
|
ysoft
|
safeq
|
A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did not enforce authent…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2022-23862
|
2024-10-31 06:21 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249780
|
9.8 |
CRITICAL
Network
|
riskengine
|
radar
|
A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Interface Handler. The manipulation with the input /../…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-10121
|
2024-10-31 06:21 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|