|
250931
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2022_23h2 windows_server_2022 windows_server_2019
|
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38262
|
2024-10-22 21:54 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250932
|
8.8 |
HIGH
Local
|
microsoft
|
azure_stack_hci
|
Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38179
|
2024-10-22 21:54 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250933
|
- |
|
-
|
-
|
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 1…
|
-
|
CVE-2024-9537
|
2024-10-22 10:00 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250934
|
7.4 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2022_23h2 windows_server_2022 windows_server_2019
|
Windows Remote Desktop Services Tampering Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43456
|
2024-10-22 06:28 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250935
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps excel office office_long_term_servicing_channel
|
Microsoft Excel Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43504
|
2024-10-22 06:26 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250936
|
5.4 |
MEDIUM
Network
|
exceedone
|
exment
|
Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When accessing the edit screen containing custom columns (column type: images or files), …
|
CWE-79
Cross-site Scripting
|
CVE-2024-47793
|
2024-10-22 06:25 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250937
|
9.8 |
CRITICAL
Network
|
microsoft
|
visual_studio_code
|
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
|
NVD-CWE-noinfo
|
CVE-2024-43488
|
2024-10-22 06:05 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250938
|
6.1 |
MEDIUM
Network
|
comfy
|
comfyui
|
A stored cross-site scripting (XSS) vulnerability exists in comfyanonymous/comfyui version 0.2.2 and possibly earlier. The vulnerability occurs when an attacker uploads an HTML file containing a mali…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10099
|
2024-10-22 06:03 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250939
|
7.1 |
HIGH
Network
|
microsoft
|
windows_server_2022_23h2 windows_server_2022 windows_server_2019 windows_10_1809 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_11_…
|
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43615
|
2024-10-22 06:00 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250940
|
5.4 |
MEDIUM
Network
|
fahadmahmood
|
rss_feed_widget
|
The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rfw-youtube-videos shortcode in all versions up to, and including, 2.9.9 due to insufficient inp…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10057
|
2024-10-22 05:53 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|