|
308051
|
- |
|
-
|
-
|
An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package
|
-
|
CVE-2024-51240
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308052
|
- |
|
-
|
-
|
The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring auth…
|
-
|
CVE-2024-51362
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308053
|
- |
|
-
|
-
|
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog and the standalone …
|
CWE-79 CWE-80
Cross-site Scripting Basic XSS
|
CVE-2024-49377
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308054
|
- |
|
-
|
-
|
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious X…
|
-
|
CVE-2024-51132
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308055
|
- |
|
-
|
-
|
WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.
|
-
|
CVE-2024-48312
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308056
|
- |
|
-
|
-
|
Under certain conditions, access to service libraries is granted to account they should not have access to.
|
-
|
CVE-2023-29122
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308057
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2024. N…
|
-
|
CVE-2024-50315
|
2024-11-7 03:15 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308058
|
5.4 |
MEDIUM
Network
|
phpgurukul
|
online_shopping_portal
|
A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/assets/plugins/DataTables/media/unit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10753
|
2024-11-7 02:42 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308059
|
7.1 |
HIGH
Network
|
akamai
|
secure_internet_access_enterprise_threatavert
|
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incor…
|
CWE-863
Incorrect Authorization
|
CVE-2024-45164
|
2024-11-7 02:35 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308060
|
8.1 |
HIGH
Network
|
qbittorrent
|
qbittorrent
|
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
|
CWE-295
Improper Certificate Validation
|
CVE-2024-51774
|
2024-11-7 02:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|