|
250111
|
5.4 |
MEDIUM
Network
|
mayurik
|
best_house_rental_management_system
|
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=tenants of the com…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10348
|
2024-10-30 22:03 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250112
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10033
|
2024-10-30 12:15 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250113
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.
|
-
|
CVE-2024-48450
|
2024-10-30 06:35 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250114
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into the tracker comments page.
|
-
|
CVE-2024-48448
|
2024-10-30 06:35 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250115
|
- |
|
-
|
-
|
HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.
|
-
|
CVE-2024-30132
|
2024-10-30 06:35 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250116
|
5.5 |
MEDIUM
Local
|
wibu
|
wibukey
|
An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulti…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-45182
|
2024-10-30 06:35 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250117
|
8.8 |
HIGH
Network
|
italtel
|
embrace
|
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser…
|
NVD-CWE-noinfo
|
CVE-2024-31842
|
2024-10-30 06:35 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250118
|
- |
|
-
|
-
|
Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issu…
|
-
|
CVE-2024-44069
|
2024-10-30 06:35 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250119
|
5.4 |
MEDIUM
Network
|
mecodia
|
feripro
|
Feripro <= v2.2.3 is vulnerable to Cross Site Scripting (XSS) via "/admin/programm/<program_id>/zuordnung/veranstaltungen/<event_id>" through the "school" input field.
|
CWE-79
Cross-site Scripting
|
CVE-2024-41519
|
2024-10-30 06:35 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250120
|
5.3 |
MEDIUM
Network
|
litestream
|
litestream
|
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-th…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-41254
|
2024-10-30 06:35 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|