|
309751
|
5.4 |
MEDIUM
Network
|
hp
|
poly_clariti_manager_firmware
|
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.
|
CWE-79
Cross-site Scripting
|
CVE-2024-41911
|
2024-10-29 06:35 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309752
|
3.3 |
LOW
Local
|
rd_labs_llc
|
who
|
The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-40096
|
2024-10-29 06:35 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309753
|
5.3 |
MEDIUM
Network
|
mecodia
|
feripro
|
An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2.2.3 allows remote attackers to get a list of all users and their corresponding …
|
NVD-CWE-Other
|
CVE-2024-41517
|
2024-10-29 06:35 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309754
|
- |
|
-
|
-
|
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-37295. Reason: This candidate is a reservation duplicate of CVE-2024-37295. Notes: All CVE users should reference CVE-2024-3729…
|
-
|
CVE-2024-36811
|
2024-10-29 06:15 |
2024-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309755
|
- |
|
-
|
-
|
Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-329163861.
|
-
|
CVE-2024-47031
|
2024-10-29 05:35 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309756
|
- |
|
-
|
-
|
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-315191818.
|
-
|
CVE-2024-47030
|
2024-10-29 05:35 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309757
|
- |
|
-
|
-
|
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrar…
|
-
|
CVE-2024-45262
|
2024-10-29 05:35 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309758
|
- |
|
-
|
-
|
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows ot…
|
-
|
CVE-2024-45261
|
2024-10-29 05:35 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309759
|
- |
|
-
|
-
|
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereb…
|
-
|
CVE-2024-45260
|
2024-10-29 05:35 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309760
|
- |
|
-
|
-
|
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download int…
|
-
|
CVE-2024-45259
|
2024-10-29 05:35 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|