|
306201
|
8.8 |
HIGH
Network
|
-
|
-
|
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replac…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-10962
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306202
|
- |
|
-
|
-
|
An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious Ja…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8648
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306203
|
- |
|
-
|
-
|
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2024-7404
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306204
|
- |
|
-
|
-
|
A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirec…
|
CWE-601
Open Redirect
|
CVE-2024-11207
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306205
|
- |
|
-
|
-
|
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-…
|
-
|
CVE-2024-10977
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306206
|
- |
|
-
|
-
|
A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit …
|
-
|
CVE-2024-7730
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306207
|
- |
|
-
|
-
|
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-b…
|
-
|
CVE-2024-3447
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306208
|
- |
|
-
|
-
|
A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the …
|
-
|
CVE-2023-4458
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306209
|
- |
|
-
|
-
|
Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker could modify Webhook poli…
|
-
|
CVE-2022-31666
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306210
|
- |
|
-
|
-
|
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed…
|
CWE-863
Incorrect Authorization
|
CVE-2024-9693
|
2024-11-15 22:58 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|