|
304861
|
9.8 |
CRITICAL
Network
|
anisha
|
job_recruitment
|
A vulnerability, which was classified as critical, was found in code-projects Job Recruitment 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument email leads…
|
CWE-89
SQL Injection
|
CVE-2024-11077
|
2024-11-15 03:57 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304862
|
9.8 |
CRITICAL
Network
|
gaizhenbiao
|
chuanhuchatgpt
|
A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including user upload, direct…
|
CWE-22
Path Traversal
|
CVE-2024-5982
|
2024-11-15 03:52 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304863
|
2.7 |
LOW
Network
|
themeisle
|
multiple_page_generator
|
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() function in al…
|
CWE-22
Path Traversal
|
CVE-2024-10672
|
2024-11-15 03:49 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304864
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()
This was found by a static analyzer.…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-50259
|
2024-11-15 03:24 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304865
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
macsec: Fix use-after-free while sending the offloading packet
KASAN reports the following UAF. The metadata_dst, which is used t…
|
CWE-416
Use After Free
|
CVE-2024-50261
|
2024-11-15 03:24 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304866
|
5.4 |
MEDIUM
Network
|
miraheze
|
wikidiscover
|
WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a special page that lists all wikis on the wiki farm. However, the special page …
|
CWE-79 CWE-80
Cross-site Scripting Basic XSS
|
CVE-2024-47782
|
2024-11-15 03:19 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304867
|
6.1 |
MEDIUM
Network
|
miraheze
|
createwiki
|
CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user can insert arbitrary HTML that is displa…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47781
|
2024-11-15 03:19 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304868
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-51689. Reason: This candidate is a reservation duplicate of CVE-2024-51689. Notes: All CVE users should reference …
|
-
|
CVE-2024-10686
|
2024-11-15 03:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304869
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: fix crash when config small gso_max_size/gso_ipv4_max_size
Config a small gso_max_size/gso_ipv4_max_size will lead to an und…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2024-50258
|
2024-11-15 03:12 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304870
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: Fix use-after-free in get_info()
ip6table_nat module unload has refcnt warning for UAF. call trace is:
WARNING: CPU: …
|
CWE-416
Use After Free
|
CVE-2024-50257
|
2024-11-15 03:11 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|