|
250621
|
8.8 |
HIGH
Network
|
brandonwhite
|
author_discussion
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion allows Blind SQL Injection.This issue affects Author Discussion: …
|
CWE-89
SQL Injection
|
CVE-2024-49609
|
2024-10-25 00:25 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250622
|
6.1 |
MEDIUM
Network
|
avchat.net
|
avchat_video_chat
|
Cross-Site Request Forgery (CSRF) vulnerability in Avchat.Net AVChat Video Chat allows Stored XSS.This issue affects AVChat Video Chat: from n/a through 2.2.
|
CWE-352
Origin Validation Error
|
CVE-2024-49605
|
2024-10-24 23:57 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250623
|
6.1 |
MEDIUM
Network
|
edush_maxim
|
googledrive_folder_list
|
Cross-Site Request Forgery (CSRF) vulnerability in Edush Maxim GoogleDrive folder list allows Stored XSS.This issue affects GoogleDrive folder list: from n/a through 2.2.2.
|
CWE-352
Origin Validation Error
|
CVE-2024-49335
|
2024-10-24 23:50 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250624
|
8.8 |
HIGH
Network
|
themeisle
|
multiple_page_generator
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows SQL Injection.This issue affects Multiple P…
|
CWE-89
SQL Injection
|
CVE-2024-47325
|
2024-10-24 23:43 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250625
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: Fix memory leak in dpaa2_switch_acl_entry_add() and dpaa2_switch_acl_entry_remove()
The cmd_buff needs to be freed …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2022-48957
|
2024-10-24 23:41 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250626
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
This commit addresses a null pointer derefere…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-49913
|
2024-10-24 23:39 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250627
|
7.2 |
HIGH
Network
|
princelycesar
|
hospital_management_system
|
SQL Injection vulnerability in hospital management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.
|
CWE-89
SQL Injection
|
CVE-2024-48657
|
2024-10-24 23:38 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250628
|
4.8 |
MEDIUM
Network
|
angeljudesuarez
|
student_management_system
|
Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2024-48656
|
2024-10-24 23:37 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250629
|
9.8 |
CRITICAL
Network
|
brandonclark
|
sitebuilder_dynamic_components
|
Deserialization of Untrusted Data vulnerability in Brandon Clark SiteBuilder Dynamic Components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through 1.0.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-49625
|
2024-10-24 23:37 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250630
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7915: fix oops on non-dbdc mt7986
mt7915_band_config() sets band_idx = 1 on the main phy for mt7986
with MT7975_ONE…
|
NVD-CWE-noinfo
|
CVE-2024-47715
|
2024-10-24 23:35 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|