|
309551
|
8.8 |
HIGH
Network
|
formosasoft
|
ee-class
|
The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify and delete datab…
|
CWE-89
SQL Injection
|
CVE-2024-9980
|
2024-10-18 03:03 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309552
|
7.2 |
HIGH
Network
|
cacti
|
cacti
|
Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing onl…
|
CWE-94
Code Injection
|
CVE-2024-43363
|
2024-10-18 02:58 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309553
|
2.4 |
LOW
Network
|
authzed
|
spicedb
|
SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResource…
|
NVD-CWE-Other
|
CVE-2024-48909
|
2024-10-18 02:56 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309554
|
7.5 |
HIGH
Network
|
ss-proj
|
shirasagi
|
SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved …
|
CWE-22
Path Traversal
|
CVE-2024-46898
|
2024-10-18 02:52 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309555
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2022_23h2 windows_server_2022 windows_server_2019
|
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43541
|
2024-10-18 02:50 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309556
|
6.5 |
MEDIUM
Adjacent
|
microsoft
|
windows_server_2022_23h2 windows_10_1809 windows_server_2019 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_11_24h2
|
Windows Mobile Broadband Driver Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43542
|
2024-10-18 02:40 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309557
|
- |
|
-
|
-
|
An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the…
|
-
|
CVE-2024-48779
|
2024-10-18 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309558
|
6.5 |
MEDIUM
Network
|
paytium
|
paytium
|
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions …
|
CWE-862
Missing Authorization
|
CVE-2023-7294
|
2024-10-18 02:34 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309559
|
4.3 |
MEDIUM
Network
|
paytium
|
paytium
|
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versi…
|
CWE-862
Missing Authorization
|
CVE-2023-7293
|
2024-10-18 02:33 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309560
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed.
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-39440
|
2024-10-18 02:33 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|