|
314621
|
5.3 |
MEDIUM
Network
|
ethyca
|
fides
|
Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-45052
|
2024-09-7 03:18 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314622
|
7.5 |
HIGH
Network
|
zyxel
|
nebula_lte3301-plus_firmware nebula_fwa505_firmware nebula_fwa710_firmware nebula_fwa510_firmware wx5600-t0_firmware wx3401-b0_firmware wx3100-t0_firmware scr50axe_firmware px…
|
A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) condition…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-5412
|
2024-09-7 03:07 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314623
|
7.5 |
HIGH
Network
|
transsion
|
carlcare
|
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
|
NVD-CWE-noinfo
|
CVE-2024-7697
|
2024-09-7 03:04 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314624
|
8.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it.
Malicious software running in a guest VM that exposes virtio_scsi can exploi…
|
CWE-909
Missing Initialization of Resource
|
CVE-2024-8178
|
2024-09-7 02:35 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314625
|
8.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing.
Malicious software running in a guest VM that exposes virtio_scsi c…
|
CWE-416
Use After Free
|
CVE-2024-45063
|
2024-09-7 02:35 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314626
|
- |
|
-
|
-
|
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
|
-
|
CVE-2024-42919
|
2024-09-7 02:35 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314627
|
- |
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
|
-
|
CVE-2024-42557
|
2024-09-7 02:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314628
|
7.5 |
HIGH
Network
|
rust-bitcoin
|
miniscript
|
The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44073
|
2024-09-7 02:35 |
2024-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314629
|
- |
|
-
|
-
|
The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include…
|
-
|
CVE-2024-6459
|
2024-09-7 02:35 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314630
|
9.8 |
CRITICAL
Network
|
totolink
|
lr350_firmware
|
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-…
|
NVD-CWE-noinfo
|
CVE-2024-42967
|
2024-09-7 02:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|