|
307561
|
7.5 |
HIGH
Network
|
nasa
|
cryptolib
|
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).
|
CWE-125
Out-of-bounds Read
|
CVE-2024-44910
|
2024-10-7 23:27 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307562
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box
[Why]
Coverity reports OVERRUN warning. soc.n…
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-46811
|
2024-10-7 23:24 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307563
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: added NULL check at start of dc_validate_stream
[Why]
prevent invalid memory access
[How]
check if dc and strea…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46802
|
2024-10-7 23:21 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307564
|
7.5 |
HIGH
Network
|
ays-pro
|
chatgpt_assistant
|
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and …
|
NVD-CWE-noinfo
|
CVE-2024-7714
|
2024-10-7 23:21 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307565
|
6.1 |
MEDIUM
Network
|
honeywell
|
iq3xcite_firmware
|
A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2024-46453
|
2024-10-7 22:53 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307566
|
6.1 |
MEDIUM
Network
|
filamentphp
|
filament
|
Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values pass…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47186
|
2024-10-7 22:30 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307567
|
7.5 |
HIGH
Network
|
netflix
|
e2nest
|
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
|
CWE-22
Path Traversal
|
CVE-2024-9301
|
2024-10-7 22:12 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307568
|
5.4 |
MEDIUM
Network
|
blockspare
|
blockspare
|
The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8325
|
2024-10-7 21:37 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307569
|
7.5 |
HIGH
Network
|
pixelyoursite
|
pixelyoursite
|
The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 a…
|
CWE-287
Improper Authentication
|
CVE-2024-7870
|
2024-10-7 21:29 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307570
|
- |
|
-
|
-
|
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed fo…
|
-
|
CVE-2024-20094
|
2024-10-7 13:15 |
2024-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|