|
250621
|
8.8 |
HIGH
Network
|
apa
|
apa_banner_slider
|
Cross-Site Request Forgery (CSRF) vulnerability in Apa Apa Banner Slider allows SQL Injection.This issue affects Apa Banner Slider: from n/a through 1.0.0.
|
CWE-352
Origin Validation Error
|
CVE-2024-49622
|
2024-10-24 23:25 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250622
|
6.5 |
MEDIUM
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to wait dio completion
It should wait all existing dio write IOs before block removal,
otherwise, previous direct write…
|
NVD-CWE-noinfo
|
CVE-2024-47726
|
2024-10-24 23:24 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250623
|
8.8 |
HIGH
Network
|
hasanmovahed
|
duplicate_title_validate
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hasan Movahed Duplicate Title Validate allows Blind SQL Injection.This issue affects Duplicate Ti…
|
CWE-89
SQL Injection
|
CVE-2024-49623
|
2024-10-24 23:18 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250624
|
5.4 |
MEDIUM
Network
|
mdabdulkader
|
easy_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Md Abdul Kader Easy Addons for Elementor allows Stored XSS.This issue affects Easy Addons …
|
CWE-79
Cross-site Scripting
|
CVE-2024-49631
|
2024-10-24 23:12 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250625
|
7.8 |
HIGH
Local
|
sangoma
|
certified_asterisk asterisk
|
An issue was discovered in Sangoma Asterisk through 18.20.0, 19.x and 20.x through 20.5.0, and 21.x through 21.0.0, and Certified Asterisk through 18.9-cert5. In manager.c, the functions action_getco…
|
CWE-22
Path Traversal
|
CVE-2024-49215
|
2024-10-24 23:10 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250626
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
af_unix: Don't return OOB skb in manage_oob().
syzbot reported use-after-free in unix_stream_recv_urg(). [0]
The scenario is
…
|
CWE-416
Use After Free
|
CVE-2024-47711
|
2024-10-24 23:03 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250627
|
9.8 |
CRITICAL
Network
|
elecom
|
wab-i1750-ps_firmware wab-s1167-ps_firmware
|
Stack-based buffer overflow vulnerability exists in WAB-I1750-PS and WAB-S1167-PS. By processing a specially crafted HTTP request, arbitrary code may be executed.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-43689
|
2024-10-24 23:02 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250628
|
7.5 |
HIGH
Network
|
wellchoose
|
administrative_management_system
|
Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server.
|
CWE-22
Path Traversal
|
CVE-2024-10200
|
2024-10-24 22:57 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250629
|
7.2 |
HIGH
Network
|
total-soft
|
ts_poll
|
The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
|
CWE-89
SQL Injection
|
CVE-2024-8625
|
2024-10-24 22:56 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250630
|
8.8 |
HIGH
Network
|
wellchoose
|
administrative_management_system
|
Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-10201
|
2024-10-24 22:56 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|