|
307231
|
- |
|
-
|
-
|
The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code.
|
-
|
CVE-2024-9139
|
2024-10-15 21:57 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307232
|
- |
|
-
|
-
|
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading t…
|
-
|
CVE-2024-9137
|
2024-10-15 21:57 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307233
|
- |
|
-
|
-
|
Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishin…
|
-
|
CVE-2024-38863
|
2024-10-15 21:57 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307234
|
- |
|
-
|
-
|
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to …
|
-
|
CVE-2024-38862
|
2024-10-15 21:57 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307235
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthenticated remote attackers still can download arbitrary system files, which may …
|
-
|
CVE-2024-9924
|
2024-10-15 21:57 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307236
|
- |
|
-
|
-
|
netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `ge…
|
CWE-89
SQL Injection
|
CVE-2024-7099
|
2024-10-15 21:57 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307237
|
- |
|
-
|
-
|
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test
credentials in the firmware binary
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-8070
|
2024-10-15 21:57 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307238
|
- |
|
-
|
-
|
A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function sendEmail of the file /qilecms/user/controller/Forget.php of the component Verifica…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2024-9907
|
2024-10-15 21:57 |
2024-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307239
|
- |
|
-
|
-
|
A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. The mani…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-9904
|
2024-10-15 21:57 |
2024-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307240
|
- |
|
-
|
-
|
A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of the…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-9903
|
2024-10-15 21:57 |
2024-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|