|
308261
|
9.8 |
CRITICAL
Network
|
dataease
|
dataease
|
DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-47074
|
2024-11-13 04:52 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308262
|
7.8 |
HIGH
Local
|
workbooth_project
|
workbooth
|
Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.
|
NVD-CWE-noinfo
|
CVE-2024-9576
|
2024-11-13 04:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308263
|
7.5 |
HIGH
Network
|
finrota
|
finrota
|
Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
|
CWE-202 CWE-311 CWE-312
Exposure of Sensitive Information Through Data Queries Missing Encryption of Sensitive Data Cleartext Storage of Sensitive Information
|
CVE-2024-6400
|
2024-11-13 04:32 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308264
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2024-6443
|
2024-11-13 04:29 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308265
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.
|
-
|
CVE-2024-51213
|
2024-11-13 03:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308266
|
- |
|
-
|
-
|
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= fiel…
|
-
|
CVE-2024-51026
|
2024-11-13 03:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308267
|
- |
|
-
|
-
|
A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an attacker to execute arbitrary SQL commands via the "searchdata " parameter.
|
-
|
CVE-2024-50989
|
2024-11-13 03:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308268
|
- |
|
-
|
-
|
The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attri…
|
-
|
CVE-2023-40457
|
2024-11-13 03:35 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308269
|
4.4 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which …
|
CWE-59
Link Following
|
CVE-2024-45770
|
2024-11-13 03:15 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308270
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
|
-
|
CVE-2024-45769
|
2024-11-13 03:15 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|