|
303691
|
8.1 |
HIGH
Network
|
apereo
|
central_authentication_service
|
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiratio…
|
CWE-613
Insufficient Session Expiration
|
CVE-2024-11208
|
2024-11-20 04:38 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303692
|
- |
|
-
|
-
|
PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft a malicious .PYM file containing…
|
-
|
CVE-2024-50636
|
2024-11-20 04:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303693
|
- |
|
-
|
-
|
SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.
|
-
|
CVE-2024-25254
|
2024-11-20 04:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303694
|
9.8 |
CRITICAL
Network
|
synology
|
photos beephotos
|
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photo…
|
CWE-77
Command Injection
|
CVE-2024-10443
|
2024-11-20 04:15 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303695
|
9.8 |
CRITICAL
Network
|
apereo
|
central_authentication_service
|
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authe…
|
CWE-287
Improper Authentication
|
CVE-2024-11209
|
2024-11-20 04:14 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303696
|
9.8 |
CRITICAL
Network
|
dataprom
|
personnel_attendance_control_systems_\/_access_control_security_systems
|
Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection.This issue affects Personne…
|
CWE-346
Origin Validation Error
|
CVE-2024-10534
|
2024-11-20 04:08 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303697
|
8.8 |
HIGH
Network
|
microsoft
|
sql_server_2016 sql_server_2017 sql_server_2019
|
SQL Server Native Client Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-48993
|
2024-11-20 04:06 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303698
|
5.4 |
MEDIUM
Network
|
k5n
|
webcalendar
|
A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can …
|
CWE-79
Cross-site Scripting
|
CVE-2024-1097
|
2024-11-20 04:05 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303699
|
9.8 |
CRITICAL
Network
|
tp-link
|
vn020-f3v\(t\)_firmware
|
A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Pars…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-11237
|
2024-11-20 04:04 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303700
|
6.1 |
MEDIUM
Network
|
pyload
|
pyload
|
An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this…
|
CWE-601
Open Redirect
|
CVE-2024-1240
|
2024-11-20 04:04 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|