|
250801
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps excel office office_long_term_servicing_channel
|
Microsoft Excel Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43504
|
2024-10-22 06:26 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250802
|
5.4 |
MEDIUM
Network
|
exceedone
|
exment
|
Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When accessing the edit screen containing custom columns (column type: images or files), …
|
CWE-79
Cross-site Scripting
|
CVE-2024-47793
|
2024-10-22 06:25 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250803
|
9.8 |
CRITICAL
Network
|
microsoft
|
visual_studio_code
|
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
|
NVD-CWE-noinfo
|
CVE-2024-43488
|
2024-10-22 06:05 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250804
|
6.1 |
MEDIUM
Network
|
comfy
|
comfyui
|
A stored cross-site scripting (XSS) vulnerability exists in comfyanonymous/comfyui version 0.2.2 and possibly earlier. The vulnerability occurs when an attacker uploads an HTML file containing a mali…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10099
|
2024-10-22 06:03 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250805
|
7.1 |
HIGH
Network
|
microsoft
|
windows_server_2022_23h2 windows_server_2022 windows_server_2019 windows_10_1809 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_11_…
|
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43615
|
2024-10-22 06:00 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250806
|
5.4 |
MEDIUM
Network
|
fahadmahmood
|
rss_feed_widget
|
The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rfw-youtube-videos shortcode in all versions up to, and including, 2.9.9 due to insufficient inp…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10057
|
2024-10-22 05:53 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250807
|
5.5 |
MEDIUM
Local
|
microsoft
|
defender_for_endpoint
|
Microsoft Defender for Endpoint for Linux Spoofing Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43614
|
2024-10-22 05:50 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250808
|
4.7 |
MEDIUM
Network
|
microsoft
|
power_bi_report_server
|
Power BI Report Server Spoofing Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43612
|
2024-10-22 05:48 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250809
|
7.8 |
HIGH
Local
|
microsoft
|
office 365_apps office_long_term_servicing_channel
|
Microsoft Office Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43616
|
2024-10-22 05:47 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250810
|
9.8 |
CRITICAL
Network
|
rittal
|
iot_interface_firmware cmc_iii_processing_units_firmware
|
The devices are vulnerable to session hijacking due to insufficient
entropy in its session ID generation algorithm. The session IDs are
predictable, with only 32,768 possible values per user, which…
|
CWE-331
Insufficient Entropy
|
CVE-2024-47945
|
2024-10-22 04:41 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|