|
249001
|
4.7 |
MEDIUM
Local
|
ivanti
|
secure_access_client
|
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
|
CWE-362
Race Condition
|
CVE-2024-29211
|
2024-11-15 04:09 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249002
|
7.8 |
HIGH
Local
|
adobe
|
after_effects
|
After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation o…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47442
|
2024-11-15 04:09 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249003
|
7.8 |
HIGH
Local
|
adobe
|
after_effects
|
After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation o…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47441
|
2024-11-15 04:09 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249004
|
9.8 |
CRITICAL
Network
|
angeljudesuarez
|
tailoring_management_system
|
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability affects unknown code of the file /incadd.php. The manipulation of the argument inc…
|
CWE-89
SQL Injection
|
CVE-2024-11074
|
2024-11-15 04:06 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249005
|
9.8 |
CRITICAL
Network
|
anisha
|
job_recruitment
|
A vulnerability, which was classified as critical, was found in code-projects Job Recruitment 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument email leads…
|
CWE-89
SQL Injection
|
CVE-2024-11077
|
2024-11-15 03:57 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249006
|
6.5 |
MEDIUM
Network
|
olland
|
horsemanager
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Olland.Biz Horsemanager allows Blind SQL Injection.This issue affects Horsemanager: from n/a thro…
|
CWE-89
SQL Injection
|
CVE-2024-51843
|
2024-11-15 03:53 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249007
|
9.8 |
CRITICAL
Network
|
gaizhenbiao
|
chuanhuchatgpt
|
A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including user upload, direct…
|
CWE-22
Path Traversal
|
CVE-2024-5982
|
2024-11-15 03:52 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249008
|
2.7 |
LOW
Network
|
themeisle
|
multiple_page_generator
|
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() function in al…
|
CWE-22
Path Traversal
|
CVE-2024-10672
|
2024-11-15 03:49 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249009
|
6.5 |
MEDIUM
Network
|
andsonsdesign
|
wp-contest
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SONS Creative Development WP Contest allows SQL Injection.This issue affects WP Contest: from n/a…
|
CWE-89
SQL Injection
|
CVE-2024-51837
|
2024-11-15 03:43 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249010
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
macsec: Fix use-after-free while sending the offloading packet
KASAN reports the following UAF. The metadata_dst, which is used t…
|
CWE-416
Use After Free
|
CVE-2024-50261
|
2024-11-15 03:24 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|