|
309171
|
6.1 |
MEDIUM
Network
|
flatpress
|
flatpress
|
A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field.
|
CWE-79
Cross-site Scripting
|
CVE-2024-25412
|
2024-10-8 00:04 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309172
|
7.5 |
HIGH
Network
|
nasa
|
cryptolib
|
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).
|
CWE-125
Out-of-bounds Read
|
CVE-2024-44912
|
2024-10-8 00:00 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309173
|
7.5 |
HIGH
Network
|
nasa
|
cryptolib
|
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_aos.c).
|
CWE-125
Out-of-bounds Read
|
CVE-2024-44911
|
2024-10-8 00:00 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309174
|
7.5 |
HIGH
Network
|
nasa
|
cryptolib
|
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).
|
CWE-125
Out-of-bounds Read
|
CVE-2024-44910
|
2024-10-7 23:27 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309175
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box
[Why]
Coverity reports OVERRUN warning. soc.n…
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-46811
|
2024-10-7 23:24 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309176
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: added NULL check at start of dc_validate_stream
[Why]
prevent invalid memory access
[How]
check if dc and strea…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46802
|
2024-10-7 23:21 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309177
|
7.5 |
HIGH
Network
|
ays-pro
|
chatgpt_assistant
|
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and …
|
NVD-CWE-noinfo
|
CVE-2024-7714
|
2024-10-7 23:21 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309178
|
6.1 |
MEDIUM
Network
|
honeywell
|
iq3xcite_firmware
|
A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2024-46453
|
2024-10-7 22:53 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309179
|
6.1 |
MEDIUM
Network
|
filamentphp
|
filament
|
Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values pass…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47186
|
2024-10-7 22:30 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309180
|
7.5 |
HIGH
Network
|
netflix
|
e2nest
|
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
|
CWE-22
Path Traversal
|
CVE-2024-9301
|
2024-10-7 22:12 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|