|
309151
|
- |
|
-
|
-
|
A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.
|
CWE-617
Reachable Assertion
|
CVE-2024-8768
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309152
|
- |
|
-
|
-
|
Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
|
-
|
CVE-2024-38860
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309153
|
- |
|
-
|
-
|
Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-21743
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309154
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web…
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2024-7873
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309155
|
- |
|
-
|
-
|
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory
|
-
|
CVE-2024-46362
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309156
|
- |
|
-
|
-
|
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename
|
-
|
CVE-2024-46085
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309157
|
- |
|
-
|
-
|
Rejected reason: DoS issues, or unexploitable crashes, are out of scope for vulnerabilities.
|
-
|
CVE-2023-36268
|
2024-09-20 18:15 |
2024-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309158
|
- |
|
-
|
-
|
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
|
-
|
CVE-2024-8963
|
2024-09-20 10:00 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309159
|
9.8 |
CRITICAL
Network
|
tenda
|
o6_firmware
|
Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-46049
|
2024-09-20 09:39 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309160
|
9.8 |
CRITICAL
Network
|
tenda
|
fh451_firmware
|
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
|
CWE-77
Command Injection
|
CVE-2024-46048
|
2024-09-20 09:35 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|