|
309251
|
5.4 |
MEDIUM
Network
|
perfexcrm
|
perfex_crm
|
A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8867
|
2024-09-17 19:55 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309252
|
4.9 |
MEDIUM
Network
|
composio
|
composio
|
A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file composio\server\api.py. The manipulation of the arg…
|
CWE-22
Path Traversal
|
CVE-2024-8865
|
2024-09-17 19:50 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309253
|
8.8 |
HIGH
Network
|
composio
|
composio
|
A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculator of the file python/composio/tools/local/mathema…
|
CWE-94
Code Injection
|
CVE-2024-8864
|
2024-09-17 19:38 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309254
|
- |
|
-
|
-
|
Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.
|
-
|
CVE-2024-8039
|
2024-09-17 11:35 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309255
|
8.1 |
HIGH
Network
|
dell
|
smartfabric_os10
|
Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentia…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-39585
|
2024-09-17 11:15 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309256
|
8.8 |
HIGH
Network
|
-
|
-
|
Windows MSHTML Platform Spoofing Vulnerability
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2024-43461
|
2024-09-17 10:00 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309257
|
9.8 |
CRITICAL
Network
|
progress
|
whatsup_gold
|
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
|
CWE-89
SQL Injection
|
CVE-2024-6670
|
2024-09-17 10:00 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309258
|
8.8 |
HIGH
Network
|
asterisk
|
asterisk certified_asterisk
|
Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an A…
|
NVD-CWE-Other
|
CVE-2024-42365
|
2024-09-17 05:23 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309259
|
9.8 |
CRITICAL
Network
|
sonicwall
|
sonicos
|
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the fi…
|
NVD-CWE-noinfo
|
CVE-2024-40766
|
2024-09-17 04:48 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309260
|
8.8 |
HIGH
Network
|
xwiki
|
pro_macros
|
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform …
|
CWE-74
Injection
|
CVE-2024-42489
|
2024-09-17 04:46 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|