|
312041
|
7.5 |
HIGH
Network
|
draytek
|
vigor2620_firmware vigor2915_firmware vigor2866_firmware vigor2766_firmware vigor2865_firmware vigor2765_firmware vigor2763_firmware vigor2135_firmware vigor166_firmware vi…
|
An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG o…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2024-41594
|
2024-10-9 00:31 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312042
|
5.5 |
MEDIUM
Network
|
cisco
|
nexus_dashboard_fabric_controller
|
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to pe…
|
CWE-88
Argument Injection
|
CVE-2024-20444
|
2024-10-9 00:26 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312043
|
8.6 |
HIGH
Network
|
cisco
|
nexus_dashboard_fabric_controller
|
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensiti…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-20448
|
2024-10-9 00:25 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312044
|
8.6 |
HIGH
Network
|
cisco
|
nexus_dashboard_orchestrator nexus_dashboard_insights nexus_dashboard_fabric_controller
|
A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-20490
|
2024-10-9 00:15 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312045
|
6.1 |
MEDIUM
Network
|
berqier
|
berqwp
|
The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9344
|
2024-10-9 00:06 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312046
|
8.8 |
HIGH
Network
|
cisco
|
rv340_dual_wan_gigabit_vpn_router_firmware rv340w_dual_wan_gigabit_wireless-ac_vpn_router_firmware rv345_dual_wan_gigabit_vpn_router_firmware rv345p_dual_wan_gigabit_poe_vpn_router_firmware
|
A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate pr…
|
NVD-CWE-noinfo
|
CVE-2024-20393
|
2024-10-8 23:37 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312047
|
9.8 |
CRITICAL
Network
|
codezips
|
online_shopping_portal
|
A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username …
|
CWE-89
SQL Injection
|
CVE-2024-9460
|
2024-10-8 23:33 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312048
|
5.4 |
MEDIUM
Network
|
sulu
|
sulu
|
Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47618
|
2024-10-8 23:31 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312049
|
7.2 |
HIGH
Network
|
cisco
|
unified_computing_system
|
A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, remote attacker with administrative privileges to pe…
|
CWE-77
Command Injection
|
CVE-2024-20365
|
2024-10-8 23:28 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312050
|
6.1 |
MEDIUM
Network
|
sulu
|
sulu
|
Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle comp…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47617
|
2024-10-8 23:23 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|