|
304601
|
4.4 |
MEDIUM
Local
|
lollms
|
lollms
|
A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to read any folder in the personality_folder on the v…
|
CWE-23
Relative Path Traversal
|
CVE-2024-6985
|
2024-11-16 02:10 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304602
|
5.5 |
MEDIUM
Local
|
lenovo
|
dolby_vision_provisioning
|
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on t…
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-5474
|
2024-11-16 02:00 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304603
|
9.1 |
CRITICAL
Network
|
github
|
enterprise_server
|
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-9487
|
2024-11-16 01:57 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304604
|
7.5 |
HIGH
Network
|
gradio_project
|
gradio
|
Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to in…
|
NVD-CWE-Other
|
CVE-2024-47867
|
2024-11-16 01:44 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304605
|
9.8 |
CRITICAL
Network
|
pedalo
|
pedalo_connector
|
The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. T…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-9822
|
2024-11-16 01:41 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304606
|
- |
|
-
|
-
|
parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload process. The XSS vulne…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-5125
|
2024-11-16 01:35 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304607
|
7.8 |
HIGH
Local
|
samsung
|
android
|
Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behavi…
|
NVD-CWE-noinfo
|
CVE-2024-34662
|
2024-11-16 01:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304608
|
6.1 |
MEDIUM
Network
|
alist_project
|
alist
|
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47067
|
2024-11-16 01:28 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304609
|
8.8 |
HIGH
Network
|
microsoft
|
sql_server_2016 sql_server_2017 sql_server_2019
|
SQL Server Native Client Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-49012
|
2024-11-16 01:16 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304610
|
8.8 |
HIGH
Network
|
microsoft
|
sql_server_2016 sql_server_2017 sql_server_2019
|
SQL Server Native Client Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-49011
|
2024-11-16 01:16 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|