|
251171
|
- |
|
-
|
-
|
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation …
|
-
|
CVE-2023-39593
|
2024-10-21 09:15 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251172
|
- |
|
-
|
-
|
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the Mari…
|
-
|
CVE-2023-26785
|
2024-10-21 09:15 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251173
|
- |
|
-
|
-
|
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it ca…
|
-
|
CVE-2024-46292
|
2024-10-21 09:15 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251174
|
8.8 |
HIGH
Network
|
ninjaforms
|
ninja_forms
|
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
|
CWE-352
Origin Validation Error
|
CVE-2024-39628
|
2024-10-20 21:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251175
|
4.3 |
MEDIUM
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of …
|
NVD-CWE-noinfo
|
CVE-2024-43789
|
2024-10-19 10:13 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251176
|
8.2 |
HIGH
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, catego…
|
NVD-CWE-noinfo
|
CVE-2024-45051
|
2024-10-19 10:11 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251177
|
4.3 |
MEDIUM
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta a…
|
NVD-CWE-noinfo
|
CVE-2024-45297
|
2024-10-19 10:06 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251178
|
6.1 |
MEDIUM
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message and replying to it. This i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47772
|
2024-10-19 09:58 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251179
|
5.4 |
MEDIUM
Network
|
newtype
|
webeip
|
NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site Script…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9969
|
2024-10-19 09:51 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251180
|
4.9 |
MEDIUM
Network
|
usualtool
|
usualtoolcms
|
A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the a…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-9917
|
2024-10-19 09:49 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|