|
307801
|
7.8 |
HIGH
Local
|
workbooth_project
|
workbooth
|
Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.
|
NVD-CWE-noinfo
|
CVE-2024-9576
|
2024-11-13 04:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307802
|
7.5 |
HIGH
Network
|
finrota
|
finrota
|
Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
|
CWE-202 CWE-311 CWE-312
Exposure of Sensitive Information Through Data Queries Missing Encryption of Sensitive Data Cleartext Storage of Sensitive Information
|
CVE-2024-6400
|
2024-11-13 04:32 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307803
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2024-6443
|
2024-11-13 04:29 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307804
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.
|
-
|
CVE-2024-51213
|
2024-11-13 03:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307805
|
- |
|
-
|
-
|
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= fiel…
|
-
|
CVE-2024-51026
|
2024-11-13 03:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307806
|
- |
|
-
|
-
|
A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an attacker to execute arbitrary SQL commands via the "searchdata " parameter.
|
-
|
CVE-2024-50989
|
2024-11-13 03:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307807
|
- |
|
-
|
-
|
The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attri…
|
-
|
CVE-2023-40457
|
2024-11-13 03:35 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307808
|
4.4 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which …
|
CWE-59
Link Following
|
CVE-2024-45770
|
2024-11-13 03:15 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307809
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
|
-
|
CVE-2024-45769
|
2024-11-13 03:15 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307810
|
- |
|
-
|
-
|
UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.
|
-
|
CVE-2024-48322
|
2024-11-13 02:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|