|
256421
|
6.1 |
MEDIUM
Network
|
wpextended
|
wp_extended
|
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up to, and including, 3.0.8 d…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8117
|
2024-09-7 01:04 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256422
|
6.5 |
MEDIUM
Network
|
bitapps
|
bit_form
|
Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bit Form Pro: from n/a through 2.6.4.
|
CWE-863
Incorrect Authorization
|
CVE-2024-43250
|
2024-09-7 01:02 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256423
|
7.8 |
HIGH
Local
|
samsung
|
notes
|
Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.
|
CWE-22
Path Traversal
|
CVE-2024-34656
|
2024-09-7 00:57 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256424
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
regulator: da9211: Use irq handler when ready
If the system does not come from reset (like when it is kexec()), the
regulator mig…
|
NVD-CWE-noinfo
|
CVE-2022-48891
|
2024-09-7 00:39 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256425
|
8.1 |
HIGH
Network
|
flowiseai
|
flowise
|
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restri…
|
CWE-287
Improper Authentication
|
CVE-2024-8181
|
2024-09-7 00:35 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256426
|
3.3 |
LOW
Local
|
samsung
|
android
|
Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.
|
NVD-CWE-noinfo
|
CVE-2024-34641
|
2024-09-7 00:27 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256427
|
9.8 |
CRITICAL
Network
|
hp
|
poly_clariti_manager_firmware
|
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.
|
NVD-CWE-noinfo
|
CVE-2024-41912
|
2024-09-7 00:13 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256428
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
scsi: storvsc: Fix swiotlb bounce buffer leak in confidential VM
storvsc_queuecommand() maps the scatter/gather list using scsi_d…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2022-48890
|
2024-09-7 00:11 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256429
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: sof-nau8825: fix module alias overflow
The maximum name length for a platform_device_id entry is 20 characters
inclu…
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2022-48889
|
2024-09-7 00:08 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256430
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Remove rcu locks from user resources
User resource lookups used rcu to avoid two extra atomics. Unfortunately
the rcu…
|
NVD-CWE-noinfo
|
CVE-2022-48887
|
2024-09-6 23:55 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|