|
307861
|
4.8 |
MEDIUM
Network
|
classroombookings
|
classroombookings
|
A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some unknown processing of the file /sessions of the component Session Page. The ma…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9807
|
2024-10-17 23:44 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307862
|
4.8 |
MEDIUM
Network
|
classroombookings
|
classroombookings
|
A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnerability affects unknown code of the file /rooms/fields of the component Room Pag…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9806
|
2024-10-17 23:44 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307863
|
7.8 |
HIGH
Local
|
deltaww
|
cncsoft-g2
|
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47964
|
2024-10-17 23:37 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307864
|
7.8 |
HIGH
Local
|
deltaww
|
cncsoft-g2
|
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47963
|
2024-10-17 23:37 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307865
|
7.8 |
HIGH
Local
|
deltaww
|
cncsoft-g2
|
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a mal…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47962
|
2024-10-17 23:37 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307866
|
7.8 |
HIGH
Local
|
deltaww
|
cncsoft-g2
|
Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute …
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-47966
|
2024-10-17 23:36 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307867
|
7.8 |
HIGH
Local
|
deltaww
|
cncsoft-g2
|
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page …
|
CWE-125
Out-of-bounds Read
|
CVE-2024-47965
|
2024-10-17 23:36 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307868
|
6.1 |
MEDIUM
Network
|
rems
|
profile_registration_without_reload\/refresh
|
A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9799
|
2024-10-17 23:32 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307869
|
4.3 |
MEDIUM
Adjacent
|
dell
|
emc_appsync
|
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to in…
|
CWE-611
XXE
|
CVE-2024-39586
|
2024-10-17 23:30 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307870
|
7.2 |
HIGH
Network
|
lylme
|
lylme_spage
|
A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The manipulation of the argument id leads to sql inject…
|
CWE-89
SQL Injection
|
CVE-2024-9790
|
2024-10-17 23:26 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|