|
307241
|
- |
|
-
|
-
|
An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec exe…
|
-
|
CVE-2024-48232
|
2024-10-31 04:35 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307242
|
7.5 |
HIGH
Network
|
emqx
|
nanomq
|
An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).
|
NVD-CWE-noinfo
|
CVE-2024-44460
|
2024-10-31 04:35 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307243
|
5.3 |
MEDIUM
Network
|
hyperledger
|
fabric
|
Hyperledger Fabric through 2.5.9 does not verify that a request has a timestamp within the expected time window.
|
NVD-CWE-noinfo
|
CVE-2024-45244
|
2024-10-31 04:35 |
2024-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307244
|
- |
|
-
|
-
|
Incomplete system memory cleanup in SEV firmware could
allow a privileged attacker to corrupt guest private memory, potentially
resulting in a loss of data integrity.
|
-
|
CVE-2023-31356
|
2024-10-31 04:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307245
|
- |
|
-
|
-
|
A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.
|
-
|
CVE-2023-20512
|
2024-10-31 04:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307246
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
riscv: fix race when vmap stack overflow
Currently, when detecting vmap stack overflow, riscv firstly switches
to the so called s…
|
CWE-362
Race Condition
|
CVE-2022-49001
|
2024-10-31 03:58 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307247
|
6.1 |
MEDIUM
Network
|
butlerblog
|
wp-members
|
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9231
|
2024-10-31 03:56 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307248
|
7.5 |
HIGH
Network
|
esafenet
|
cdg
|
A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the file /com/esafenet/servlet/client/DecryptApplicationS…
|
CWE-22
Path Traversal
|
CVE-2024-10379
|
2024-10-31 03:54 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307249
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. Parsing a maliciously crafted file may lead to an unexpect…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44284
|
2024-10-31 03:48 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307250
|
9.8 |
CRITICAL
Network
|
codezips
|
pet_shop_management_system
|
A vulnerability, which was classified as critical, has been found in Codezips Pet Shop Management System 1.0. This issue affects some unknown processing of the file /animalsupdate.php. The manipulati…
|
CWE-89
SQL Injection
|
CVE-2024-10430
|
2024-10-31 03:48 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|