|
306411
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
CWE-843
Type Confusion
|
CVE-2024-10230
|
2024-10-31 17:35 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306412
|
8.8 |
HIGH
Network
|
projectworlds
|
online_time_table_generator
|
A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashbo…
|
CWE-89
SQL Injection
|
CVE-2024-10447
|
2024-10-31 10:23 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306413
|
5.3 |
MEDIUM
Network
|
cisco
|
adaptive_security_appliance_software
|
A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for the SSH server o…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-20526
|
2024-10-31 10:08 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306414
|
6.5 |
MEDIUM
Network
|
libsndfile_project
|
libsndfile
|
libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.
|
CWE-617
Reachable Assertion
|
CVE-2024-50613
|
2024-10-31 09:58 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306415
|
7.5 |
HIGH
Network
|
sun.net
|
ehdr_ctms
|
The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain f…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-10438
|
2024-10-31 09:52 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306416
|
7.5 |
HIGH
Network
|
sun.net
|
ehdr_ctms
|
The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-10439
|
2024-10-31 09:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306417
|
9.8 |
CRITICAL
Network
|
sun.net
|
ehdr_ctms
|
The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents.
|
CWE-89
SQL Injection
|
CVE-2024-10440
|
2024-10-31 09:34 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306418
|
8.8 |
HIGH
Network
|
oretnom23
|
packers_and_movers_management_system
|
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page…
|
CWE-89
SQL Injection
|
CVE-2024-48427
|
2024-10-31 09:07 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306419
|
7.8 |
HIGH
Local
|
google
|
android
|
In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no addi…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47035
|
2024-10-31 09:05 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306420
|
5.5 |
MEDIUM
Local
|
dell
|
data_lakehouse
|
Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with…
|
CWE-89
SQL Injection
|
CVE-2024-47483
|
2024-10-31 09:01 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|