|
305541
|
7.4 |
HIGH
Network
|
linuxfoundation
|
harbor
|
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution …
|
CWE-863
Incorrect Authorization
|
CVE-2022-31671
|
2024-11-20 00:40 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305542
|
7.2 |
HIGH
Network
|
mayurik
|
best_employee_management_system
|
A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulati…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11214
|
2024-11-20 00:38 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305543
|
9.8 |
CRITICAL
Network
|
icdsoft
|
multimanager_wp
|
The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the user impersona…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-11028
|
2024-11-20 00:38 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305544
|
- |
|
-
|
-
|
In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which e…
|
-
|
CVE-2024-10103
|
2024-11-20 00:35 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305545
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to the PDF preview component.
|
-
|
CVE-2024-33231
|
2024-11-20 00:35 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305546
|
- |
|
-
|
-
|
StepSecurity's Harden-Runner provides network egress filtering and runtime security for GitHub-hosted and self-hosted runners. Versions of step-security/harden-runner prior to v2.10.2 contain multipl…
|
CWE-78
OS Command
|
CVE-2024-52587
|
2024-11-20 00:35 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305547
|
- |
|
-
|
-
|
AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.
|
-
|
CVE-2024-51051
|
2024-11-20 00:35 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305548
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.
|
-
|
CVE-2024-51053
|
2024-11-20 00:35 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305549
|
- |
|
-
|
-
|
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via…
|
-
|
CVE-2024-50848
|
2024-11-20 00:35 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305550
|
- |
|
-
|
-
|
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2024-52303
|
2024-11-20 00:35 |
2024-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|