|
311701
|
- |
|
-
|
-
|
Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor…
|
-
|
CVE-2024-41590
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311702
|
- |
|
-
|
-
|
The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters pa…
|
-
|
CVE-2024-41588
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311703
|
- |
|
-
|
-
|
DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject …
|
-
|
CVE-2024-41585
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311704
|
- |
|
-
|
-
|
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate acc…
|
-
|
CVE-2024-42514
|
2024-10-8 04:37 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311705
|
5.4 |
MEDIUM
Network
|
connekthq
|
ajax_load_more
|
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8505
|
2024-10-8 04:26 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311706
|
6.1 |
MEDIUM
Network
|
goldplugins
|
custom_banners
|
The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8799
|
2024-10-8 04:22 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311707
|
8.8 |
HIGH
Network
|
plugingarden
|
wp_easy_gallery
|
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient e…
|
CWE-89
SQL Injection
|
CVE-2024-9018
|
2024-10-8 04:20 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311708
|
5.0 |
MEDIUM
Network
|
openstack redhat
|
heat openstack_platform
|
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and th…
|
NVD-CWE-noinfo
|
CVE-2024-7319
|
2024-10-8 04:15 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311709
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47527
|
2024-10-8 04:08 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311710
|
5.4 |
MEDIUM
Network
|
librenms
|
librenms
|
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitra…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47525
|
2024-10-8 04:08 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|