|
308131
|
4.3 |
MEDIUM
Adjacent
|
acronis
|
cyber_protect
|
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
|
NVD-CWE-Other
|
CVE-2024-49384
|
2024-10-16 22:52 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308132
|
7.8 |
HIGH
Local
|
electronics.jtekt
|
kostac_plc_programming_software
|
Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project f…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47134
|
2024-10-16 22:50 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308133
|
8.8 |
HIGH
Network
|
rems
|
drag_and_drop_image_upload
|
A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.php. The manipulati…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-9975
|
2024-10-16 22:44 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308134
|
9.8 |
CRITICAL
Network
|
code-projects
|
pharmacy_management_system
|
A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_customer.php?action=search. The manipulatio…
|
CWE-89
SQL Injection
|
CVE-2024-9976
|
2024-10-16 22:42 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308135
|
5.5 |
MEDIUM
Local
|
adobe
|
acrobat
|
Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabilit…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-39379
|
2024-10-16 22:38 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308136
|
6.8 |
MEDIUM
Network
|
adobe
|
commerce magento
|
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could l…
|
CWE-22
Path Traversal
|
CVE-2024-39406
|
2024-10-16 22:37 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308137
|
4.3 |
MEDIUM
Network
|
adobe
|
commerce magento
|
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features a…
|
CWE-352
Origin Validation Error
|
CVE-2024-39408
|
2024-10-16 22:36 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308138
|
4.3 |
MEDIUM
Network
|
adobe
|
commerce magento
|
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features a…
|
CWE-352
Origin Validation Error
|
CVE-2024-39409
|
2024-10-16 22:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308139
|
4.3 |
MEDIUM
Network
|
adobe
|
commerce magento
|
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features a…
|
CWE-352
Origin Validation Error
|
CVE-2024-39410
|
2024-10-16 22:34 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308140
|
5.4 |
MEDIUM
Network
|
flatpress
|
flatpress
|
FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the conte…
|
CWE-79
Cross-site Scripting
|
CVE-2024-33209
|
2024-10-16 22:33 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|