|
306371
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
|
CWE-89
SQL Injection
|
CVE-2024-48229
|
2024-11-1 00:49 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306372
|
4.9 |
MEDIUM
Network
|
funadmin
|
funadmin
|
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).
|
NVD-CWE-noinfo
|
CVE-2024-48227
|
2024-11-1 00:48 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306373
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
|
CWE-89
SQL Injection
|
CVE-2024-48223
|
2024-11-1 00:44 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306374
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
|
CWE-89
SQL Injection
|
CVE-2024-48222
|
2024-11-1 00:44 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306375
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
|
CWE-89
SQL Injection
|
CVE-2024-48218
|
2024-11-1 00:44 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306376
|
9.1 |
CRITICAL
Network
|
langchain
|
langchain
|
A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite ex…
|
CWE-22
Path Traversal
|
CVE-2024-7774
|
2024-11-1 00:39 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306377
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
|
CWE-89
SQL Injection
|
CVE-2024-48226
|
2024-11-1 00:38 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306378
|
6.5 |
MEDIUM
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
|
NVD-CWE-noinfo
|
CVE-2024-48225
|
2024-11-1 00:35 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306379
|
- |
|
-
|
-
|
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configurat…
|
-
|
CVE-2024-20280
|
2024-11-1 00:35 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306380
|
- |
|
-
|
-
|
Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting …
|
-
|
CVE-2023-31310
|
2024-11-1 00:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|