|
307021
|
7.5 |
HIGH
Network
|
ivanti
|
avalanche
|
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-47007
|
2024-10-16 22:23 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307022
|
6.7 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_10_1507 windows_server_2016 windows_server_2022_23h2 windows_10_1809 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_10_22h2 windows…
|
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37983
|
2024-10-16 22:15 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307023
|
9.8 |
CRITICAL
Network
|
alisonic
|
sibylla_firmware
|
Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.
|
CWE-89
SQL Injection
|
CVE-2024-8630
|
2024-10-16 22:15 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307024
|
7.5 |
HIGH
Network
|
opentext
|
cx-e_voice
|
Path Traversal vulnerability discovered in OpenText™ CX-E Voice,
affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.
|
CWE-22
Path Traversal
|
CVE-2023-7260
|
2024-10-16 21:53 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307025
|
- |
|
-
|
-
|
There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This …
|
-
|
CVE-2024-9858
|
2024-10-16 18:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307026
|
- |
|
-
|
-
|
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead…
|
CWE-1270
Generation of Incorrect Security Tokens
|
CVE-2023-32188
|
2024-10-16 18:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307027
|
- |
|
-
|
-
|
A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies t…
|
-
|
CVE-2023-22650
|
2024-10-16 18:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307028
|
- |
|
-
|
-
|
The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewer code fields in versions up to, and including, 3.0.0-beta.4 due to insufficien…
|
CWE-79
Cross-site Scripting
|
CVE-2023-7296
|
2024-10-16 17:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307029
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.21 due to insufficient input sanitization and out…
|
CWE-79
Cross-site Scripting
|
CVE-2023-7295
|
2024-10-16 17:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307030
|
- |
|
-
|
-
|
The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an accordion slider in all versions up to, and including, 1.9.11 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9582
|
2024-10-16 16:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|