|
312531
|
5.4 |
MEDIUM
Network
|
stitionai
|
devika
|
A stored cross site scripting vulnerabilities exists in DevikaAI from commit 6acce21fb08c3d1123ef05df6a33912bf0ee77c2 onwards via improperly decoded user input.
|
CWE-79
Cross-site Scripting
|
CVE-2024-7790
|
2024-08-21 04:27 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312532
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_advanced_web_application_firewall big-ip_analytics big-ip_application_acceleration_manager big-ip_application_secur…
|
Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
|
NVD-CWE-noinfo
|
CVE-2024-41723
|
2024-08-21 04:26 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312533
|
7.8 |
HIGH
Local
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …
|
CWE-416
Use After Free
|
CVE-2024-39383
|
2024-08-21 04:26 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312534
|
5.3 |
MEDIUM
Network
|
f5
|
big-ip_next_central_manager
|
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
|
CWE-287
Improper Authentication
|
CVE-2024-37028
|
2024-08-21 04:26 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312535
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_advanced_web_application_firewall big-ip_analytics big-ip_application_acceleration_manager big-ip_application_secur…
|
In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization.
…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-41727
|
2024-08-21 04:25 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312536
|
5.5 |
MEDIUM
Local
|
xpdfreader
|
xpdf
|
In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
|
CWE-674
Uncontrolled Recursion
|
CVE-2024-7866
|
2024-08-21 04:23 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312537
|
9.8 |
CRITICAL
Network
|
kevinwong
|
online_food_ordering_system
|
A vulnerability was found in itsourcecode Online Food Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcategory.php. The manipu…
|
CWE-89
SQL Injection
|
CVE-2024-7838
|
2024-08-21 04:16 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312538
|
7.5 |
HIGH
Network
|
celsiusbenelux
|
comfortkey
|
A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information about the und…
|
CWE-22
Path Traversal
|
CVE-2024-27120
|
2024-08-21 04:08 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312539
|
8.8 |
HIGH
Network
|
rems
|
task_progress_tracker
|
A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been classified as critical. Affected is an unknown function of the file /endpoint/delete-task.php. The manipulation of t…
|
CWE-89
SQL Injection
|
CVE-2024-7792
|
2024-08-21 04:08 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312540
|
- |
|
-
|
-
|
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.
|
-
|
CVE-2024-33872
|
2024-08-21 03:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|