|
308141
|
- |
|
-
|
-
|
Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may re…
|
-
|
CVE-2024-42496
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308142
|
- |
|
-
|
-
|
Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to the device may exploit the d…
|
-
|
CVE-2024-41999
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308143
|
- |
|
-
|
-
|
In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-based buffer overflow upon deserialization of session informatio…
|
-
|
CVE-2024-45200
|
2024-09-30 17:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308144
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
powerpc/qspinlock: Fix deadlock in MCS queue
If an interrupt occurs in queued_spin_lock_slowpath() after we increment
qnodesp->co…
|
CWE-667
Improper Locking
|
CVE-2024-46797
|
2024-09-30 00:15 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308145
|
7.5 |
HIGH
Network
|
rapidscada
|
rapid_scada
|
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
|
CWE-521
Weak Password Requirements
|
CVE-2024-47221
|
2024-09-29 09:45 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308146
|
6.5 |
MEDIUM
Network
|
zte
|
mf296r_firmware
|
There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of servic…
|
CWE-787
Out-of-bounds Write
|
CVE-2022-39068
|
2024-09-29 09:41 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308147
|
4.8 |
MEDIUM
Network
|
decidim
|
decidim
|
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the…
|
CWE-79
Cross-site Scripting
|
CVE-2024-39910
|
2024-09-29 09:33 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308148
|
6.1 |
MEDIUM
Network
|
rws
|
multitrans
|
Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2024-43024
|
2024-09-29 09:27 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308149
|
5.6 |
MEDIUM
Local
|
microsoft
|
windows_11_22h2 windows_11_23h2
|
Windows Kernel Information Disclosure Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37985
|
2024-09-29 09:26 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308150
|
4.9 |
MEDIUM
Network
|
ibm
|
business_automation_workflow
|
IBM Business Automation Workflow
22.0.2, 23.0.1, 23.0.2, and 24.0.0
could allow a privileged user to perform unauthorized activities due to improper client side validation.
|
NVD-CWE-Other
|
CVE-2024-43188
|
2024-09-29 09:24 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|