|
307731
|
- |
|
-
|
-
|
DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.
|
-
|
CVE-2024-41584
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307732
|
- |
|
-
|
-
|
DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name.
|
-
|
CVE-2024-41583
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307733
|
- |
|
-
|
-
|
Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly i…
|
CWE-440
Expected Behavior Violation
|
CVE-2024-47762
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307734
|
- |
|
-
|
-
|
TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. This file system serves as the basis for the HTT…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-41988
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307735
|
- |
|
-
|
-
|
The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exp…
|
CWE-352
Origin Validation Error
|
CVE-2024-41987
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307736
|
- |
|
-
|
-
|
Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files.
|
-
|
CVE-2024-45872
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307737
|
- |
|
-
|
-
|
Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).
|
-
|
CVE-2024-45871
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307738
|
- |
|
-
|
-
|
NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference by running nvdisasm on a malformed ELF file. A s…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-0125
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307739
|
- |
|
-
|
-
|
NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed memory by running it on a malformed ELF file. A succ…
|
CWE-416
Use After Free
|
CVE-2024-0124
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307740
|
- |
|
-
|
-
|
NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into runnin…
|
CWE-1285
Improper Validation of Specified Index, Position, or Offset in Input
|
CVE-2024-0123
|
2024-10-4 22:50 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|