|
312981
|
5.4 |
MEDIUM
Network
|
cryoutcreations
|
parabola
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Parabola allows Stored XSS.This issue affects Parabola: from n/a through 2…
|
CWE-79
Cross-site Scripting
|
CVE-2024-44058
|
2024-09-23 23:28 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312982
|
5.4 |
MEDIUM
Network
|
cryoutcreations
|
fluida
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Fluida allows Stored XSS.This issue affects Fluida: from n/a through 1.8.8.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44054
|
2024-09-23 23:23 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312983
|
7.8 |
HIGH
Local
|
intel
|
raid_web_console
|
Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
|
NVD-CWE-noinfo
|
CVE-2024-34543
|
2024-09-23 23:17 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312984
|
5.7 |
MEDIUM
Adjacent
|
intel
|
raid_web_console
|
Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.
|
NVD-CWE-noinfo
|
CVE-2024-36261
|
2024-09-23 23:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312985
|
5.7 |
MEDIUM
Adjacent
|
intel
|
raid_web_console
|
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacent access.
|
NVD-CWE-noinfo
|
CVE-2024-36247
|
2024-09-23 23:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312986
|
5.7 |
MEDIUM
Adjacent
|
intel
|
raid_web_console
|
Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable information disclosure via adjacent access.
|
NVD-CWE-noinfo
|
CVE-2024-34545
|
2024-09-23 23:13 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312987
|
6.5 |
MEDIUM
Adjacent
|
espressif
|
esp-now
|
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not differentiated …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2024-42483
|
2024-09-23 23:06 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312988
|
7.8 |
HIGH
Local
|
refuel
|
autolabel
|
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user cr…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2024-27320
|
2024-09-23 22:56 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312989
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_mobile
|
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary…
|
NVD-CWE-Other
|
CVE-2024-45833
|
2024-09-23 22:43 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312990
|
7.5 |
HIGH
Network
|
vidco
|
voc_tester
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal.This issue affects VOC TESTER: before 12.34.8.
|
CWE-22
Path Traversal
|
CVE-2024-7609
|
2024-09-23 18:15 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|