|
310171
|
- |
|
-
|
-
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostn…
|
CWE-200 CWE-359
Information Exposure Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2024-46979
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310172
|
- |
|
-
|
-
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user,…
|
CWE-648
Incorrect Use of Privileged APIs
|
CVE-2024-46978
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310173
|
- |
|
-
|
-
|
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.
|
-
|
CVE-2023-41610
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310174
|
- |
|
-
|
-
|
Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using …
|
CWE-284
Improper Access Control
|
CVE-2024-46990
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310175
|
- |
|
-
|
-
|
find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is …
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2024-45813
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310176
|
- |
|
-
|
-
|
Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the password reset function. While setting up SMTP e-mail's on my server, I tested said…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2024-45298
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310177
|
- |
|
-
|
-
|
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.
|
-
|
CVE-2023-47105
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310178
|
- |
|
-
|
-
|
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a malicious…
|
-
|
CVE-2024-45858
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310179
|
- |
|
-
|
-
|
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.
|
-
|
CVE-2024-44542
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310180
|
- |
|
-
|
-
|
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
|
-
|
CVE-2024-35515
|
2024-09-20 21:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|