|
308681
|
9.8 |
CRITICAL
Network
|
d7y
|
dragonfly
|
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2023-27584
|
2024-09-26 02:28 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308682
|
6.5 |
MEDIUM
Network
|
envoyproxy
|
envoy
|
Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2024-45808
|
2024-09-26 02:18 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308683
|
5.3 |
MEDIUM
Network
|
jflow_project
|
jflow
|
A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.…
|
NVD-CWE-Other
|
CVE-2024-9003
|
2024-09-26 02:18 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308684
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management in the codec. To …
|
NVD-CWE-noinfo
|
CVE-2024-45807
|
2024-09-26 02:12 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308685
|
5.4 |
MEDIUM
Network
|
cryoutcreations
|
kahuna
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Kahuna allows Stored XSS.This issue affects Kahuna: from n/a through 1.7.0.
|
CWE-79
Cross-site Scripting
|
CVE-2024-43994
|
2024-09-26 02:09 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308686
|
7.5 |
HIGH
Network
|
trianglemicroworks siemens
|
iec_61850_source_code_library sicam_a8000_firmware sicam_scc_firmware sicam_egs_firmware sicam_s8000 sitipe_at
|
Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in …
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-34057
|
2024-09-26 02:08 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308687
|
8.8 |
HIGH
Network
|
frogcms_project
|
frogcms
|
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123
|
CWE-352
Origin Validation Error
|
CVE-2024-46086
|
2024-09-26 02:08 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308688
|
7.5 |
HIGH
Network
|
quinn_project
|
quinn
|
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, `refuse()`, or `ignore()` an `…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2024-45311
|
2024-09-26 02:03 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308689
|
7.5 |
HIGH
Network
|
linlinjava
|
litemall
|
A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminGoodscontroller.java.
|
CWE-89
SQL Injection
|
CVE-2024-46382
|
2024-09-26 01:56 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308690
|
8.8 |
HIGH
Network
|
frogcms_project
|
frogcms
|
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
|
CWE-352
Origin Validation Error
|
CVE-2024-46394
|
2024-09-26 01:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|