|
312791
|
4.3 |
MEDIUM
Network
|
lenovo
|
xclarity_administrator
|
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
|
NVD-CWE-noinfo
|
CVE-2024-45103
|
2024-09-19 10:50 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312792
|
6.5 |
MEDIUM
Network
|
lenovo
|
xclarity_administrator
|
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
|
NVD-CWE-noinfo
|
CVE-2024-45104
|
2024-09-19 10:49 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312793
|
9.8 |
CRITICAL
Network
|
heyewei
|
jfinalcms
|
A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. The manipulation of the argument name leads t…
|
CWE-22
Path Traversal
|
CVE-2024-8782
|
2024-09-19 10:46 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312794
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: Encryption procedure host vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-5754
|
2024-09-19 10:44 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312795
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: Missing length checks of net_buf in rfcomm_handle_data
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2024-6258
|
2024-09-19 10:40 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312796
|
9.8 |
CRITICAL
Network
|
mayurik
|
best_free_law_office_management
|
SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/con…
|
CWE-89
SQL Injection
|
CVE-2024-44430
|
2024-09-19 10:38 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312797
|
8.8 |
HIGH
Network
|
qdocs
|
smart_school
|
A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnerability is an unknown functionality of the file /user/chat/mynewuser of the comp…
|
CWE-89
SQL Injection
|
CVE-2024-8784
|
2024-09-19 10:38 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312798
|
5.4 |
MEDIUM
Network
|
opentibiabr
|
myaac
|
A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown function of the file system/pages/forum/new_post.php of the component Post Reply Han…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8783
|
2024-09-19 10:38 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312799
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: Unchecked user input in bap_broadcast_assistant
|
CWE-787
Out-of-bounds Write
|
CVE-2024-5931
|
2024-09-19 10:35 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312800
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT:Classic: Multiple missing buf length checks
|
CWE-369
Divide By Zero
|
CVE-2024-6135
|
2024-09-19 10:34 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|