|
250891
|
5.4 |
MEDIUM
Network
|
dankedev
|
elemenda
|
The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.0.2 due to insufficient input sanitization and output escap…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9373
|
2024-10-23 00:07 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250892
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: fix NULL pointer dereference in mt7996_mcu_sta_bfer_he
Fix the NULL pointer dereference in mt7996_mcu_sta_bfe…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-47681
|
2024-10-22 23:57 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250893
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
exfat: resolve memory leak from exfat_create_upcase_table()
If exfat_load_upcase_table reaches end and returns -EINVAL,
allocated…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-47677
|
2024-10-22 23:55 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250894
|
7.3 |
HIGH
Local
|
citrix
|
workspace
|
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
|
NVD-CWE-noinfo
|
CVE-2024-7890
|
2024-10-22 23:53 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250895
|
7.3 |
HIGH
Local
|
citrix
|
workspace
|
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
|
NVD-CWE-noinfo
|
CVE-2024-7889
|
2024-10-22 23:50 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250896
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
boat_booking_system
|
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file book-boat.php?bid=1 of the comp…
|
CWE-89
SQL Injection
|
CVE-2024-10153
|
2024-10-22 23:45 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250897
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
boat_booking_system
|
A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file status.php of the component Check Booking …
|
CWE-89
SQL Injection
|
CVE-2024-10154
|
2024-10-22 23:44 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250898
|
8.8 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underly…
|
NVD-CWE-Other
|
CVE-2024-20286
|
2024-10-22 23:44 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250899
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
boat_booking_system
|
A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the component Sign In Page. …
|
CWE-89
SQL Injection
|
CVE-2024-10156
|
2024-10-22 23:43 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250900
|
6.1 |
MEDIUM
Network
|
phpgurukul
|
boat_booking_system
|
A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been classified as problematic. This affects an unknown part of the file book-boat.php?bid=1 of the component Book a Boat Page.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10155
|
2024-10-22 23:43 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|