|
252011
|
5.4 |
MEDIUM
Network
|
cisco
|
nexus_dashboard nexus_dashboard_fabric_controller
|
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files on an affected device.
This vulnerability exis…
|
CWE-862
Missing Authorization
|
CVE-2024-20477
|
2024-10-9 01:00 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252012
|
8.2 |
HIGH
Network
|
synology
|
drive_client
|
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-16084 allows remote attackers to overwrite trivial …
|
CWE-120
Classic Buffer Overflow
|
CVE-2023-52946
|
2024-10-9 00:55 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252013
|
8.6 |
HIGH
Network
|
cisco
|
nexus_dashboard_orchestrator nexus_dashboard_insights nexus_dashboard_fabric_controller
|
A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information.
This vulnerability exists because …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-20491
|
2024-10-9 00:55 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252014
|
9.8 |
CRITICAL
Network
|
deltaww
|
diaenergie
|
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the target…
|
CWE-89
SQL Injection
|
CVE-2024-43699
|
2024-10-9 00:44 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252015
|
8.8 |
HIGH
Network
|
deltaww
|
diaenergie
|
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.
|
CWE-89
SQL Injection
|
CVE-2024-42417
|
2024-10-9 00:43 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252016
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor3912_firmware vigor2962_firmware vigor3910_firmware vigor165_firmware vigor1000b_firmware vigor166_firmware vigor2135_firmware vigor2763_firmware vigor2765_firmware vi…
|
DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-41593
|
2024-10-9 00:35 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252017
|
6.1 |
MEDIUM
Network
|
draytek
|
vigor2620_firmware vigor2915_firmware vigor2866_firmware vigor2766_firmware vigor2865_firmware vigor2765_firmware vigor2763_firmware vigor2135_firmware vigor166_firmware vi…
|
DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2024-41591
|
2024-10-9 00:34 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252018
|
6.1 |
MEDIUM
Network
|
cozmoslabs
|
membership_\&_content_restriction_-_paid_member_subscriptions
|
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9222
|
2024-10-9 00:34 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252019
|
6.1 |
MEDIUM
Network
|
ibericode
|
mailchimp_top_bar
|
The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9210
|
2024-10-9 00:34 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252020
|
8.8 |
HIGH
Network
|
cisco
|
nexus_dashboard_fabric_controller
|
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device.
This vulnerabil…
|
CWE-22
Path Traversal
|
CVE-2024-20449
|
2024-10-9 00:33 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|