|
251081
|
7.1 |
HIGH
Network
|
microsoft
|
windows_server_2022_23h2 windows_server_2022 windows_server_2019 windows_10_1809 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_11_…
|
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43615
|
2024-10-22 06:00 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251082
|
5.4 |
MEDIUM
Network
|
fahadmahmood
|
rss_feed_widget
|
The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rfw-youtube-videos shortcode in all versions up to, and including, 2.9.9 due to insufficient inp…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10057
|
2024-10-22 05:53 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251083
|
5.5 |
MEDIUM
Local
|
microsoft
|
defender_for_endpoint
|
Microsoft Defender for Endpoint for Linux Spoofing Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43614
|
2024-10-22 05:50 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251084
|
4.7 |
MEDIUM
Network
|
microsoft
|
power_bi_report_server
|
Power BI Report Server Spoofing Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43612
|
2024-10-22 05:48 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251085
|
7.8 |
HIGH
Local
|
microsoft
|
office 365_apps office_long_term_servicing_channel
|
Microsoft Office Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43616
|
2024-10-22 05:47 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251086
|
9.8 |
CRITICAL
Network
|
rittal
|
iot_interface_firmware cmc_iii_processing_units_firmware
|
The devices are vulnerable to session hijacking due to insufficient
entropy in its session ID generation algorithm. The session IDs are
predictable, with only 32,768 possible values per user, which…
|
CWE-331
Insufficient Entropy
|
CVE-2024-47945
|
2024-10-22 04:41 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251087
|
7.8 |
HIGH
Local
|
autodesk
|
revit
|
A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Stack-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, o…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7994
|
2024-10-22 03:35 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251088
|
7.8 |
HIGH
Local
|
autodesk
|
revit
|
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or exec…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7993
|
2024-10-22 03:27 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251089
|
4.9 |
MEDIUM
Network
|
oracle
|
application_express
|
Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with netw…
|
NVD-CWE-noinfo
|
CVE-2024-21261
|
2024-10-22 03:27 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251090
|
8.8 |
HIGH
Network
|
vmware
|
vmware_hcx
|
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A
malicious authenticated user with non-administrator privileges may be
able to enter specially crafted …
|
CWE-89
SQL Injection
|
CVE-2024-38814
|
2024-10-22 03:20 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|