|
256361
|
7.2 |
HIGH
Network
|
ethyca
|
fides
|
Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitization or rendering e…
|
CWE-94
Code Injection
|
CVE-2024-45053
|
2024-09-7 03:20 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256362
|
5.3 |
MEDIUM
Network
|
ethyca
|
fides
|
Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-45052
|
2024-09-7 03:18 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256363
|
7.5 |
HIGH
Network
|
zyxel
|
nebula_lte3301-plus_firmware nebula_fwa505_firmware nebula_fwa710_firmware nebula_fwa510_firmware wx5600-t0_firmware wx3401-b0_firmware wx3100-t0_firmware scr50axe_firmware px…
|
A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) condition…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-5412
|
2024-09-7 03:07 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256364
|
7.5 |
HIGH
Network
|
transsion
|
carlcare
|
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
|
NVD-CWE-noinfo
|
CVE-2024-7697
|
2024-09-7 03:04 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256365
|
8.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it.
Malicious software running in a guest VM that exposes virtio_scsi can exploi…
|
CWE-909
Missing Initialization of Resource
|
CVE-2024-8178
|
2024-09-7 02:35 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256366
|
8.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing.
Malicious software running in a guest VM that exposes virtio_scsi c…
|
CWE-416
Use After Free
|
CVE-2024-45063
|
2024-09-7 02:35 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256367
|
- |
|
-
|
-
|
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
|
-
|
CVE-2024-42919
|
2024-09-7 02:35 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256368
|
- |
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
|
-
|
CVE-2024-42557
|
2024-09-7 02:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256369
|
7.5 |
HIGH
Network
|
rust-bitcoin
|
miniscript
|
The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44073
|
2024-09-7 02:35 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256370
|
- |
|
-
|
-
|
The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include…
|
-
|
CVE-2024-6459
|
2024-09-7 02:35 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|