|
310051
|
6.1 |
MEDIUM
Network
|
discourse
|
calendar
|
Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be susceptible to XSS attacks. This vulnerability only aff…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45303
|
2024-09-19 05:25 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310052
|
6.1 |
MEDIUM
Network
|
eclipse
|
glassfish
|
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed.
This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code includ…
|
CWE-601
Open Redirect
|
CVE-2024-8646
|
2024-09-19 05:20 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310053
|
6.5 |
MEDIUM
Network
|
reedos
|
aim-star
|
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulat…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-45786
|
2024-09-19 05:12 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310054
|
7.5 |
HIGH
Network
|
reedos
|
aim-star
|
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by …
|
NVD-CWE-Other
|
CVE-2024-45788
|
2024-09-19 04:57 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310055
|
4.3 |
MEDIUM
Network
|
reedos
|
aim-star
|
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authenticated remote attacke…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2024-45789
|
2024-09-19 04:55 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310056
|
7.8 |
HIGH
Local
|
schneider-electric
|
vijeo_designer_embedded_in_ecostruxure_machine_expert vijeo_designer
|
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized
access, loss of confidentiality, integrity and availability of the workstation when non-admin
authenticated u…
|
NVD-CWE-noinfo
|
CVE-2024-8306
|
2024-09-19 04:51 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310057
|
6.7 |
MEDIUM
Local
|
dell
|
latitude_5290_2-in-1_firmware precision_3420_tower_firmware precision_3620_firmware wyse_7040_thin_client_firmware precision_7720_firmware precision_7520_firmware precision_5530_2-i…
|
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading …
|
NVD-CWE-noinfo
|
CVE-2024-38483
|
2024-09-19 04:19 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310058
|
7.8 |
HIGH
Local
|
adobe
|
audition
|
Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of thi…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-39378
|
2024-09-19 04:16 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310059
|
5.5 |
MEDIUM
Local
|
adobe
|
audition
|
Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to by…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-41868
|
2024-09-19 04:13 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310060
|
6.1 |
MEDIUM
Network
|
mayurik
|
best_house_rental_management_system
|
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file categories.php. The manip…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8708
|
2024-09-19 04:11 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|