|
256401
|
9.6 |
CRITICAL
Network
|
-
|
-
|
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
|
CWE-284
Improper Access Control
|
CVE-2024-38175
|
2024-08-21 21:30 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256402
|
- |
|
-
|
-
|
Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as t…
|
-
|
CVE-2024-6322
|
2024-08-21 21:30 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256403
|
- |
|
-
|
-
|
Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in the html of the post. The vulnerability is fixed in commit a62f711d5600e4e5d86f…
|
-
|
CVE-2024-43408
|
2024-08-21 21:30 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256404
|
- |
|
-
|
-
|
Improper Access Controls allows backend users to overwrite their username when disallowed.
|
-
|
CVE-2024-27187
|
2024-08-21 21:30 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256405
|
9.8 |
CRITICAL
Network
|
jielink\+_jsotc2016_project
|
jielink\+_jsotc2016
|
A vulnerability, which was classified as critical, has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. This issue affects some unknown processing of the f…
|
NVD-CWE-Other
|
CVE-2024-7919
|
2024-08-21 21:30 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256406
|
7.2 |
HIGH
Network
|
douco
|
douphp
|
A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php of the component F…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7917
|
2024-08-21 21:30 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256407
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-7757
|
2024-08-21 18:15 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256408
|
- |
|
-
|
-
|
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.
|
-
|
CVE-2024-42565
|
2024-08-21 06:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256409
|
- |
|
-
|
-
|
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.
|
-
|
CVE-2024-42558
|
2024-08-21 06:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256410
|
6.1 |
MEDIUM
Network
|
heytap
|
internet_browser
|
The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity compo…
|
CWE-79
Cross-site Scripting
|
CVE-2024-23729
|
2024-08-21 06:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|