|
305981
|
6.5 |
MEDIUM
Network
|
sonatype
|
nexus
|
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-5764
|
2024-11-7 01:41 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305982
|
7.2 |
HIGH
Network
|
wuzhicms
|
wuzhicms
|
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to cod…
|
CWE-94
Code Injection
|
CVE-2024-10505
|
2024-11-7 01:38 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305983
|
- |
|
-
|
-
|
Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially …
|
-
|
CVE-2023-31305
|
2024-11-7 01:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305984
|
9.8 |
CRITICAL
Network
|
esafenet
|
cdg
|
A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation …
|
CWE-89
SQL Injection
|
CVE-2024-10597
|
2024-11-7 01:28 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305985
|
5.3 |
MEDIUM
Network
|
choplugins
|
order_notification_for_telegram
|
The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nktgnfw_send_test_message' function in versions u…
|
CWE-862
Missing Authorization
|
CVE-2024-9686
|
2024-11-7 01:19 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305986
|
3.6 |
LOW
Local
|
chidiwilliams
|
buzz
|
A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function download_model of the file buzz/model_loader.py. The manipulation leads to ins…
|
CWE-377
Insecure Temporary File
|
CVE-2024-10372
|
2024-11-7 01:14 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305987
|
5.4 |
MEDIUM
Network
|
sohelwpexpert
|
awesome_buttons
|
The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization …
|
CWE-79
Cross-site Scripting
|
CVE-2024-10148
|
2024-11-7 01:02 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305988
|
7.5 |
HIGH
Network
|
63moons
|
aero wave_2.0
|
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by interceptin…
|
NVD-CWE-Other
|
CVE-2024-51561
|
2024-11-7 00:59 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305989
|
6.1 |
MEDIUM
Network
|
bna
|
pospratik
|
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects PosPratik: before v3.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9147
|
2024-11-7 00:53 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305990
|
7.5 |
HIGH
Network
|
zimaspace
|
zimaos
|
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS API endpoint `http://<Zima_Server_IP:PORT>/v3/file?t…
|
CWE-22
Path Traversal
|
CVE-2024-48931
|
2024-11-7 00:46 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|