|
308171
|
6.5 |
MEDIUM
Network
|
moxa
|
mxview_one
|
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of s…
|
CWE-22
Path Traversal
|
CVE-2024-6786
|
2024-10-1 03:31 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308172
|
4.3 |
MEDIUM
Network
|
cilium
|
cilium
|
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoute…
|
CWE-436
Interpretation Conflict
|
CVE-2024-42487
|
2024-10-1 03:31 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308173
|
8.8 |
HIGH
Network
|
lobehub
|
lobe_chat
|
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redi…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-47066
|
2024-10-1 03:03 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308174
|
5.9 |
MEDIUM
Network
|
moxa
|
mxview_one
|
This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbi…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2024-6787
|
2024-10-1 03:02 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308175
|
6.1 |
MEDIUM
Network
|
rws
|
multitrans
|
An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43025
|
2024-10-1 02:51 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308176
|
5.3 |
MEDIUM
Network
|
coffee2code
|
remember_me_controls
|
The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the bootstrap.php …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-7415
|
2024-10-1 02:46 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308177
|
8.2 |
HIGH
Network
|
scriptcase
|
scriptcase
|
Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnera…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8942
|
2024-10-1 02:39 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308178
|
7.5 |
HIGH
Network
|
linuxptp_project
|
linuxptp
|
An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function
|
NVD-CWE-noinfo
|
CVE-2024-42861
|
2024-10-1 02:35 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308179
|
6.1 |
MEDIUM
Network
|
flowiseai
|
embed flowise
|
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
|
CWE-79
Cross-site Scripting
|
CVE-2024-9148
|
2024-10-1 02:34 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308180
|
5.4 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event name was not sanitized on output. Users …
|
CWE-79
Cross-site Scripting
|
CVE-2024-7398
|
2024-10-1 01:12 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|