|
312211
|
8.8 |
HIGH
Network
|
draytek
|
vigor3900_firmware
|
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.
|
CWE-78
OS Command
|
CVE-2024-44844
|
2024-09-12 01:24 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312212
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
gsmi: fix null-deref in gsmi_get_variable
We can get EFI variables without fetching the attribute, so we must
allow for that in g…
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-52893
|
2024-09-12 01:24 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312213
|
4.3 |
MEDIUM
Network
|
ngothang
|
wp_multitasking
|
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
|
CWE-352
Origin Validation Error
|
CVE-2024-6852
|
2024-09-12 01:23 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312214
|
4.3 |
MEDIUM
Network
|
ngothang
|
wp_multitasking
|
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack
|
CWE-352
Origin Validation Error
|
CVE-2024-6853
|
2024-09-12 01:22 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312215
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/virtio: Fix GEM handle creation UAF
Userspace can guess the handle value and try to race GEM object creation
with handle clos…
|
CWE-416
Use After Free
|
CVE-2022-48899
|
2024-09-12 01:22 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312216
|
4.3 |
MEDIUM
Network
|
ngothang
|
wp_multitasking
|
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack
|
CWE-352
Origin Validation Error
|
CVE-2024-6855
|
2024-09-12 01:21 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312217
|
4.3 |
MEDIUM
Network
|
ngothang
|
wp_multitasking
|
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
|
CWE-352
Origin Validation Error
|
CVE-2024-6856
|
2024-09-12 01:20 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312218
|
5.4 |
MEDIUM
Network
|
ngothang
|
wp_multitasking
|
The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6859
|
2024-09-12 01:19 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312219
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/dp: do not complete dp_aux_cmd_fifo_tx() if irq is not for aux transfer
There are 3 possible interrupt sources are handle…
|
CWE-362
Race Condition
|
CVE-2022-48898
|
2024-09-12 01:19 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312220
|
9.8 |
CRITICAL
Network
|
themetechmount
|
truebooker
|
The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a …
|
CWE-89
SQL Injection
|
CVE-2024-6924
|
2024-09-12 01:15 |
2024-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|