|
312011
|
- |
|
-
|
-
|
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2024-45811
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312012
|
- |
|
-
|
-
|
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The `arduino-esp32` CI is vulnerable to multiple Poisoned Pipeline Execution (PPE…
|
CWE-94 CWE-20 CWE-78
Code Injection Improper Input Validation OS Command
|
CVE-2024-45798
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312013
|
- |
|
-
|
-
|
Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a …
|
-
|
CVE-2024-42503
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312014
|
- |
|
-
|
-
|
Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underly…
|
-
|
CVE-2024-42502
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312015
|
- |
|
-
|
-
|
An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system…
|
-
|
CVE-2024-42501
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312016
|
- |
|
-
|
-
|
A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead to a Denial of Service (DoS). The API used for LLM-base…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-8939
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312017
|
- |
|
-
|
-
|
A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.
|
CWE-617
Reachable Assertion
|
CVE-2024-8768
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312018
|
- |
|
-
|
-
|
Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
|
-
|
CVE-2024-38860
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312019
|
- |
|
-
|
-
|
Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-21743
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312020
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web…
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2024-7873
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|