|
307621
|
- |
|
-
|
-
|
Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.
|
-
|
CVE-2024-46658
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307622
|
- |
|
-
|
-
|
Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor…
|
-
|
CVE-2024-41590
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307623
|
- |
|
-
|
-
|
The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters pa…
|
-
|
CVE-2024-41588
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307624
|
- |
|
-
|
-
|
DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject …
|
-
|
CVE-2024-41585
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307625
|
- |
|
-
|
-
|
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate acc…
|
-
|
CVE-2024-42514
|
2024-10-8 04:37 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307626
|
5.4 |
MEDIUM
Network
|
connekthq
|
ajax_load_more
|
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8505
|
2024-10-8 04:26 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307627
|
6.1 |
MEDIUM
Network
|
goldplugins
|
custom_banners
|
The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8799
|
2024-10-8 04:22 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307628
|
8.8 |
HIGH
Network
|
plugingarden
|
wp_easy_gallery
|
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient e…
|
CWE-89
SQL Injection
|
CVE-2024-9018
|
2024-10-8 04:20 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307629
|
5.0 |
MEDIUM
Network
|
openstack redhat
|
heat openstack_platform
|
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and th…
|
NVD-CWE-noinfo
|
CVE-2024-7319
|
2024-10-8 04:15 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307630
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47527
|
2024-10-8 04:08 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|