|
312721
|
- |
|
-
|
-
|
An issue in the downloader.php component of TOSEI online store management system v4.02, v4.03, and v4.04 allows attackers to execute a directory traversal.
|
-
|
CVE-2024-43022
|
2024-08-22 03:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312722
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.
|
CWE-352
Origin Validation Error
|
CVE-2024-42608
|
2024-08-22 03:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312723
|
8.8 |
HIGH
Network
|
siamonhasan
|
warehouse_inventory_system
|
A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
|
CWE-352
Origin Validation Error
|
CVE-2024-42579
|
2024-08-22 03:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312724
|
- |
|
-
|
-
|
In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede…
|
-
|
CVE-2024-20083
|
2024-08-22 03:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312725
|
8.8 |
HIGH
Network
|
ivanti
|
endpoint_manager_mobile
|
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the ap…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-36131
|
2024-08-22 03:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312726
|
9.6 |
CRITICAL
Network
|
koha
|
koha
|
Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component.
|
CWE-79
Cross-site Scripting
|
CVE-2024-28740
|
2024-08-22 03:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312727
|
- |
|
-
|
-
|
Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software
versions before 1.979. A physically close
attacker that is authenticated to the Blueto…
|
-
|
CVE-2024-40893
|
2024-08-22 03:15 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312728
|
- |
|
-
|
-
|
A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This vulnerability allows a physically close attacker to use the license UUID for authentication and provision …
|
-
|
CVE-2024-40892
|
2024-08-22 03:15 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312729
|
7.5 |
HIGH
Network
|
tenda
|
fh1201_firmware
|
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (Do…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-42950
|
2024-08-22 02:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312730
|
- |
|
-
|
-
|
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gai…
|
-
|
CVE-2024-43411
|
2024-08-22 02:25 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|