|
309791
|
6.5 |
MEDIUM
Network
|
bitapps
|
bit_form
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit Form Pro: from n/a through 2.6.4.
|
NVD-CWE-noinfo
|
CVE-2024-43251
|
2024-09-18 03:10 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309792
|
9.6 |
CRITICAL
Network
|
joplin_project
|
joplin
|
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to d…
|
CWE-79
Cross-site Scripting
|
CVE-2024-40643
|
2024-09-18 03:03 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309793
|
6.5 |
MEDIUM
Network
|
techexcel
|
back_office_software
|
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulne…
|
CWE-863
Incorrect Authorization
|
CVE-2024-8601
|
2024-09-18 02:54 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309794
|
7.1 |
HIGH
Local
|
microsoft
|
azure_network_watcher_agent
|
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38188
|
2024-09-18 02:49 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309795
|
7.3 |
HIGH
Local
|
microsoft
|
azure_network_watcher_agent
|
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43470
|
2024-09-18 02:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309796
|
3.1 |
LOW
Adjacent
|
rapid7
|
insight_platform
|
Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of…
|
CWE-862
Missing Authorization
|
CVE-2024-8042
|
2024-09-18 02:25 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309797
|
7.5 |
HIGH
Adjacent
|
microsoft
|
windows_10_1507 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_11_24h2 windows_10_1607 windows_server_2016 windows_10_22h2 windows_11_23h2 windows…
|
Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38119
|
2024-09-18 02:23 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309798
|
9.9 |
CRITICAL
Network
|
microsoft
|
azure_web_apps
|
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.
|
NVD-CWE-noinfo
|
CVE-2024-38194
|
2024-09-18 02:02 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309799
|
9.0 |
CRITICAL
Network
|
microsoft
|
azure_stack_hub
|
Azure Stack Hub Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-38216
|
2024-09-18 02:00 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309800
|
7.5 |
HIGH
Network
|
dlink
|
di-8100_firmware
|
D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44375
|
2024-09-18 02:00 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|