Aggregator
CVE-2024-3987 | WP Mobile Menu Plugin up to 2.8.4.2 on WordPress Image Alt cross site scripting
2 months 3 weeks ago
A vulnerability was found in WP Mobile Menu Plugin up to 2.8.4.2 on WordPress. It has been classified as problematic. This affects an unknown part of the component Image Alt Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-3987. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1768 | Clever Fox Plugin up to 25.2.0 on WordPress cross site scripting
2 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Clever Fox Plugin up to 25.2.0 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-1768. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1988 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel Plugin cross site scripting
2 months 3 weeks ago
A vulnerability has been found in Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel Plugin up to 2.2.80 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-1988. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-30266 | Emerson PACSystem RXi/PACSystem RSTi-EP/Fanuc VersaMax insufficiently protected credentials (icsa-24-158-01)
2 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Emerson PACSystem RXi, PACSystem RSTi-EP and Fanuc VersaMax. Affected by this issue is some unknown functionality. The manipulation leads to insufficiently protected credentials.
This vulnerability is handled as CVE-2022-30266. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to change the configuration settings.
vuldb.com
CVE-2024-5425 | WP jQuery Lightbox Plugin up to 1.5.4 on WordPress Attribute Title cross site scripting
2 months 3 weeks ago
A vulnerability was found in WP jQuery Lightbox Plugin up to 1.5.4 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Attribute Handler. The manipulation of the argument Title leads to cross site scripting.
The identification of this vulnerability is CVE-2024-5425. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-5277 | lunary-ai lunary password recovery
2 months 3 weeks ago
A vulnerability was found in lunary-ai lunary. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery.
This vulnerability is known as CVE-2024-5277. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-33804 | campcodes Complete Web-Based School Management System 1.0 /model/get_subject.php ID sql injection
2 months 3 weeks ago
A vulnerability classified as critical was found in campcodes Complete Web-Based School Management System 1.0. This vulnerability affects unknown code of the file /model/get_subject.php. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2024-33804. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-33805 | campcodes Complete Web-Based School Management System 1.0 /model/get_student.php ID sql injection
2 months 3 weeks ago
A vulnerability was found in campcodes Complete Web-Based School Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /model/get_student.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2024-33805. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-33807 | campcodes Complete Web-Based School Management System 1.0 get_teacher_timetable.php grade sql injection
2 months 3 weeks ago
A vulnerability was found in campcodes Complete Web-Based School Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /model/get_teacher_timetable.php. The manipulation of the argument grade leads to sql injection.
This vulnerability was named CVE-2024-33807. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-33402 | Campcodes Complete Web-Based School Management System 1.0 approve_petty_cash.php ID sql injection
2 months 3 weeks ago
A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /model/approve_petty_cash.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2024-33402. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-33450 | Finereport 8.0 information disclosure
2 months 3 weeks ago
A vulnerability was found in Finereport 8.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-33450. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-27373 | Samsung Exynos 1330 slsi_nan_config_get_nl_params heap-based overflow
2 months 3 weeks ago
A vulnerability was found in Samsung Exynos 980, Exynos 850, Exynos 1280, Exynos 1380 and Exynos 1330. It has been classified as critical. This affects the function slsi_nan_config_get_nl_params. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-27373. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2024-27376 | Samsung Exynos 1330 slsi_nan_subscribe_get_nl_params heap-based overflow
2 months 3 weeks ago
A vulnerability classified as critical has been found in Samsung Exynos 980, Exynos 850, Exynos 1280, Exynos 1380 and Exynos 1330. Affected is the function slsi_nan_subscribe_get_nl_params. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-27376. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-27805 | Apple iOS/iPadOS Environment Variable information disclosure
2 months 3 weeks ago
A vulnerability was found in Apple iOS and iPadOS and classified as problematic. This issue affects some unknown processing of the component Environment Variable Handler. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-27805. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27805 | Apple macOS Environment Variable information disclosure
2 months 3 weeks ago
A vulnerability was found in Apple macOS. It has been classified as problematic. Affected is an unknown function of the component Environment Variable Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-27805. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27805 | Apple watchOS Environment Variable information disclosure
2 months 3 weeks ago
A vulnerability was found in Apple watchOS. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Environment Variable Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-27805. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27805 | Apple tvOS Environment Variable information disclosure
2 months 3 weeks ago
A vulnerability was found in Apple tvOS. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Environment Variable Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-27805. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27807 | Apple iOS/iPadOS up to 16.6/17.4 App Privacy Report
2 months 3 weeks ago
A vulnerability has been found in Apple iOS and iPadOS up to 16.6/17.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component App Privacy Report. The manipulation leads to an unknown weakness.
This vulnerability is known as CVE-2024-27807. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
IDA 9.1 & IDA 8.5 算法分析
2 months 3 weeks ago
看到分享了 8.5 安装包,之前的 kg 失效了,才发现替换成了 9.x 的注册模式。做了简单分析,整理如下。