|
308831
|
- |
|
-
|
-
|
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.
|
-
|
CVE-2024-46076
|
2024-10-10 21:57 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308832
|
- |
|
-
|
-
|
D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be…
|
-
|
CVE-2024-44674
|
2024-10-10 21:57 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308833
|
- |
|
-
|
-
|
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS versions 10.8.1 – 1121 that may allow a remote, authenticated attacker to create a crafted link that can be saved as a n…
|
CWE-79
Cross-site Scripting
|
CVE-2024-25709
|
2024-10-10 21:57 |
2024-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308834
|
- |
|
-
|
-
|
There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message th…
|
-
|
CVE-2024-25706
|
2024-10-10 21:57 |
2024-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308835
|
- |
|
-
|
-
|
There is a cross site scripting vulnerability in the Esri Portal for ArcGIS Experience Builder 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted l…
|
CWE-79
Cross-site Scripting
|
CVE-2024-25705
|
2024-10-10 21:57 |
2024-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308836
|
- |
|
-
|
-
|
An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via placing a crafted file in…
|
-
|
CVE-2024-36814
|
2024-10-10 21:56 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308837
|
- |
|
-
|
-
|
Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure via local access.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-27457
|
2024-10-10 21:56 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308838
|
- |
|
-
|
-
|
Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed in system logs which may be persisted. T…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-47822
|
2024-10-10 21:56 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308839
|
- |
|
-
|
-
|
TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/gro…
|
CWE-863
Incorrect Authorization
|
CVE-2024-47780
|
2024-10-10 21:56 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308840
|
- |
|
-
|
-
|
Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affect…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2024-47773
|
2024-10-10 21:56 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|